| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-39300 | Signature bypass via multiple root elements in node-SAML | node-saml | node-saml | High | 7.7 | 2022-10-13 00:00:00 | Deep Dive |
| CVE-2022-39299 | Signature bypass via multiple root elements in Passport-SAML | node-saml | passport-saml | High | 7.4 | 2022-10-12 00:00:00 | Deep Dive |
| CVE-2022-37011 | Siemens Mendix SAML Module 安全漏洞 | Siemens | Mendix SAML (Mendix 7 compatible) | 超危 | - | 2022-09-13 00:00:00 | Deep Dive |
| CVE-2022-1010 | Login using WordPress Users < 1.13.4 - Admin+ Stored Cross-Site Scripting | Unknown | Login using WordPress Users ( WP as SAML IDP ) | 中危 | - | 2022-06-27 08:55:59 | Deep Dive |
| CVE-2022-32286 | Siemens Mendix SAML Module 跨站脚本漏洞 | Siemens | Mendix SAML Module (Mendix 7 compatible) | 中危 | - | 2022-06-14 09:22:20 | Deep Dive |
| CVE-2022-32285 | Siemens Mendix SAML Module 代码问题漏洞 | Siemens | Mendix SAML Module (Mendix 7 compatible) | 高危 | - | 2022-06-14 09:22:19 | Deep Dive |
| CVE-2022-26493 | miniOrange SAML Authentication Bypass | Xecuify | Drupal 8 miniOrange SAML SP | Critical | 9.8 | 2022-06-03 16:00:14 | Deep Dive |
| CVE-2021-21678 | Jenkins 安全漏洞 | Jenkins project | Jenkins SAML Plugin | 高危 | - | 2021-08-31 13:50:15 | Deep Dive |
| CVE-2021-39171 | Unlimited transforms allowed for signed nodes | node-saml | passport-saml | Medium | 5.3 | 2021-08-27 22:05:11 | Deep Dive |
| CVE-2021-33712 | Mendix SAML 数据伪造问题漏洞 | Siemens | Mendix SAML Module | 高危 | - | 2021-06-08 19:47:17 | Deep Dive |
| CVE-2020-27846 | Crewjam Saml 安全漏洞 | - | crewjam/saml | 超危 | - | 2020-12-21 15:16:14 | Deep Dive |
| CVE-2019-10755 | pac4j-saml 安全特征问题漏洞 | - | PAC4J For SAML Protocol | 中危 | - | 2019-09-23 22:13:04 | Deep Dive |
| CVE-2017-11430 | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal | OmniAuth | OmnitAuth-SAML | 超危 | - | 2019-04-17 14:00:30 | Deep Dive |
| CVE-2017-11428 | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal | OneLogin | Ruby-SAML | 超危 | - | 2019-04-17 13:59:53 | Deep Dive |