| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-32600 | xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption | simplesamlphp | xml-security | High | 8.2 | 2026-03-13 19:58:42 | Deep Dive |
| CVE-2025-48995 | SignXML's signature verification with HMAC is vulnerable to a timing attack | XML-Security | signxml | - | - | 2025-06-02 16:23:28 | Deep Dive |
| CVE-2025-48994 | SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack | XML-Security | signxml | - | - | 2025-06-02 16:22:09 | Deep Dive |
| CVE-2023-49087 | Validation of SignedInfo | simplesamlphp | xml-security | Medium | 6.8 | 2023-11-30 05:20:28 | Deep Dive |
| CVE-2019-12400 | Apache Santuario 输入验证错误漏洞 | Apache | Apache Santuario - XML Security for Java | 中危 | - | 2019-08-23 20:30:33 | Deep Dive |