CWE-91
XML Injection (aka Blind XPath Injection)
The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.
116 vulnerabilities with CWE-91
CVE-2022-22784
HIGH
Zoom Client <5.10.0 - Code Injection
CVSS 8.1
CVE-2022-20729
MEDIUM
Cisco Firepower Threat Defense - Command Injection
CVSS 4.4
CVE-2022-25356
MEDIUM
Alt-N MDaemon Security Gateway <8.5.0 - XML Injection
CVSS 5.3
CVE-2022-22834
HIGH
Overit Geocall < 8.0 - Remote Code Execution
CVSS 8.8
CVE-2021-4140
CRITICAL
Firefox ESR < 91.5, Firefox < 96, Thunderbird < 91.5 - XSS
CVSS 10.0
CVE-2021-27777
HIGH
XML Parser - XXE Injection
CVSS 7.5
CVE-2021-38948
CRITICAL
IBM InfoSphere Information Server 11.7 - XXE
CVSS 9.1
CVE-2021-22524
MEDIUM
NetIQ Access Manager <5.0.1, 4.5.4 - DoS
CVSS 5.4
CVE-2021-39181
HIGH
OpenOlat <15.3.18, <15.5.3, <16.0.0 - Code Injection
CVSS 8.8
CVE-2021-36033
CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
CVSS 9.1
CVE-2021-36028
CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
CVSS 9.1
CVE-2021-36022
CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
CVSS 9.1
CVE-2021-36020
HIGH
Magento Commerce <2.4.2-2.3.7 - Code Injection
CVSS 8.2
CVE-2021-36359
HIGH
OrbiTeam BSCW Classic <7.4.3 - Authenticated RCE
CVSS 8.8
CVE-2021-32758
HIGH
OpenMage Magento LTS <19.4.15, <20.0.11 - Command Injection
CVSS 7.2
CVE-2021-37154
CRITICAL
ForgeRock AM <7.0.2 - Code Injection
CVSS 9.8
CVE-2021-32796
MEDIUM
xmldom <0.7.0 - Info Disclosure
CVSS 6.5
CVE-2021-2322
HIGH
OpenGrok <1.6.7 - RCE
CVSS 8.8
CVE-2021-31347
MEDIUM
libezxml.a <0.8.6 - Memory Corruption
CVSS 6.5
CVE-2021-21025
CRITICAL
Magento <2.4.1-2.3.6 - Code Injection
CVSS 9.1
CVE-2021-21019
CRITICAL
Magento <2.4.1-2.3.6 - Code Injection
CVSS 9.1
CVE-2020-29599
HIGH
ImageMagick <7.0.10-40 - Command Injection
CVSS 7.8
CVE-2020-29128
CRITICAL
petl <1.68 - Info Disclosure
CVSS 9.8
CVE-2020-4774
MEDIUM
IBM Curam Social Program Management <7.0.10 - Info Disclosure
CVSS 5.4
CVE-2020-25216
CRITICAL
yWorks yEd Desktop <3.20.1 - Code Injection
CVSS 9.8
Details
Vulnerabilities
116