CWE-112
8 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-112page 1 of 1
- CVE-2020-1975MEDIUMCVSS 6.8EG 6.82020-02-12
Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier …
- CVE-2020-27282MEDIUMCVSS 4.3EG 4.32021-03-15
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows privileged attackers with physical access to render the device persistently unusable by uploading specially crafted co…
- CVE-2021-1359MEDIUMCVSS 6.3EG 6.32021-07-08
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to…
- CVE-2021-27780MEDIUMCVSS 5.3EG 5.32022-05-27
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
- CVE-2022-28213HIGHCVSS 8.1EG 8.12022-04-12
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retr…
- CVE-2022-28217MEDIUMCVSS 6.5EG 6.52022-06-13
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSR…
- CVE-2023-40310MEDIUMCVSS 6.5EG 6.52023-10-10
SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, would be accessed during import. A…
- CVE-2026-1190LOWCVSS 3.1EG 3.12026-01-26
A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationDat…
Map vulnerabilities like CWE-112 to your infrastructure
EchelonGraph correlates every CVE — across CWE-112 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →