CWE-112 · 7 records
Missing XML Validation
CVEs in this class
7 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-28213Proof of concept | When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently valisap · businessobjects business intelligence platform · CWE-112 | High8.1 | — | 12.5% | Apr 12, 2022 |
36Monitor | CVE-2021-1359No exploit | Cisco Web Security Appliance Privilege Escalation Vulnerabilitycisco · web security appliance · CWE-112 | High8.8 | — | 1.9% | Jul 8, 2021 |
35Monitor | CVE-2020-1975No exploit | Missing XML Validation in PAN-OS Web Interfacepaloaltonetworks · pan-os · CWE-112 | High8.8 | — | 1.0% | Feb 12, 2020 |
30Monitor | CVE-2023-40310No exploit | Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 importsap · powerdesigner · CWE-112 | High7.5 | — | 0.8% | Oct 9, 2023 |
21Monitor | CVE-2021-27780No exploit | HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interactionhcltech · bigfix mobile · CWE-112 | Medium5.3 | — | 0.8% | May 27, 2022 |
17Monitor | CVE-2020-27282No exploit | In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows privileged attackerhamilton-medical · hamilton-t1 firmware · CWE-112 | Medium4.3 | — | 0.3% | Mar 15, 2021 |
12Monitor | CVE-2026-1190No exploit | Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdatared hat · red hat build of keycloak 26.4 · CWE-112 | Low3.1 | — | 0.4% | Jan 26, 2026 |
- CVE-2022-2821336Monitor
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently vali
HighCVSS 8.1Proof of conceptEPSS 12%sap · businessobjects business intelligence platformApr 12, 2022
- CVE-2021-135936Monitor
Cisco Web Security Appliance Privilege Escalation Vulnerability
HighCVSS 8.8No exploitEPSS 2%cisco · web security applianceJul 8, 2021
- CVE-2020-197535Monitor
Missing XML Validation in PAN-OS Web Interface
HighCVSS 8.8No exploitEPSS 1%paloaltonetworks · pan-osFeb 12, 2020
- CVE-2023-4031030Monitor
Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import
HighCVSS 7.5No exploitEPSS 1%sap · powerdesignerOct 9, 2023
- CVE-2021-2778021Monitor
HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction
MediumCVSS 5.3No exploitEPSS 1%hcltech · bigfix mobileMay 27, 2022
- CVE-2020-2728217Monitor
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows privileged attacker
MediumCVSS 4.3No exploitEPSS 0%hamilton-medical · hamilton-t1 firmwareMar 15, 2021
- CVE-2026-119012Monitor
Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdata
LowCVSS 3.1No exploitEPSS 0%red hat · red hat build of keycloak 26.4Jan 26, 2026