CWE-91
XML Injection (aka Blind XPath Injection)
The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.
116 vulnerabilities with CWE-91
CVE-2024-2648
MEDIUM
Netentsec NS-ASG 6.3 - Improper Neutralization of Data within XPath...
CVSS 4.3
CVE-2024-2645
MEDIUM
Netentsec NS-ASG Application Security Gateway 6.3 - XPath Injection
CVSS 4.3
CVE-2024-25413
HIGH
FireBear Improved Import And Export <3.8.6 - SSRF
CVSS 7.2
CVE-2023-35858
MEDIUM
Modern Campus - Omni CMS 2023.1 - Info Disclosure
CVSS 5.3
CVE-2023-32173
MEDIUM
Unified Automation UaGateway - XML Injection DoS
CVSS 5.8
CVE-2023-27328
HIGH
Parallels Desktop < 18.1.1_\(53328\) - Privilege Escalation
CVSS 7.8
CVE-2023-46214
HIGH
Splunk Enterprise <9.0.7-9.1.2 - RCE
CVSS 8.0
CVE-2023-43187
CRITICAL
NodeBB <1.18.6 - RCE
CVSS 9.8
CVE-2023-40612
MEDIUM
OpenMNS Horizon <32.0.2 - XXE Injection
CVSS 5.3
CVE-2023-38207
HIGH
Adobe Commerce <2.4.6-p1, <2.4.5-p3, <2.4.4-p4 - XML Injection
CVSS 7.5
CVE-2023-29289
MEDIUM
Adobe Commerce <2.4.6 - XML Injection
CVSS 6.5
CVE-2023-22247
HIGH
Adobe Commerce <2.4.4-p2, 2.4.5-p1 - XML Injection
CVSS 7.5
CVE-2023-27253
HIGH
Netgate pfSense <2.7.0 - Command Injection
CVSS 8.8
CVE-2023-22485
MEDIUM
Github Cmark-gfm < 0.29.0.gfm.7 - Out-of-Bounds Access
CVSS 5.3
CVE-2022-50902
HIGH
Wondershare FamiSafe 1.0 - Code Injection
CVSS 8.4
CVE-2022-32755
MEDIUM
IBM Security Directory Server - XXE
CVSS 5.5
CVE-2022-4245
MEDIUM
Codehaus-plexus Plexus-utils < 3.0.24 - XXE
CVSS 4.3
CVE-2022-46751
HIGH
Apache Ivy <2.5.2 - XML Injection
CVSS 8.2
CVE-2022-35259
HIGH
Endpoint Manager <2022.3 - Code Injection
CVSS 7.8
CVE-2022-27233
MEDIUM
Intel Quartus Prime < 21.1 - Information Disclosure
CVSS 6.5
CVE-2022-22244
MEDIUM
Juniper Networks Junos OS <19.1R3-S9, <19.2R3-S6, <19.3R3-S7, <19.4...
CVSS 5.3
CVE-2022-22243
MEDIUM
Juniper Networks Junos OS <19.1R3-S9-20 - XPath Injection
CVSS 4.3
CVE-2022-34253
HIGH
Adobe Commerce <2.4.3-p2, 2.3.7-p3, 2.4.4 - Code Injection
CVSS 7.2
CVE-2022-2458
HIGH
Redhat Process Automation Manager < 7.13.1 - XXE
CVSS 8.2
CVE-2022-33739
HIGH
CA Clarity <15.9.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
116