All CVEs (6)
CVE-2021-1359
HIGHA vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privilege...
CVE-2020-1975
HIGHMissing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This iss...
CVE-2022-28213
HIGHWhen a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, whi...
CVE-2023-40310
HIGHSAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, w...
CVE-2021-27780
MEDIUMThe software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
CVE-2020-27282
MEDIUMIn Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows privileged attackers with physical access to render the device persistently unu...