<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:30:44.962351+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06599</id>
    <title>bdu:2025-06599</title>
    <updated>2026-10-02T10:30:44.974767+00:00</updated>
    <content>bdu:2025-06599</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06599"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1001</id>
    <title>certfr-2022-avi-1001 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T10:30:44.974806+00:00</updated>
    <content>certfr-2022-avi-1001</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-1001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-215888</id>
    <title>EUVD-2026-215888</title>
    <updated>2026-10-02T10:30:44.974825+00:00</updated>
    <content>EUVD-2026-215888</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-215888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2002-20001</id>
    <title>fkie_cve-2002-20001</title>
    <updated>2026-10-02T10:30:44.974837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2002-20001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jx4r-qc68-xjr5</id>
    <title>GHSA-jx4r-qc68-xjr5</title>
    <updated>2026-10-02T10:30:44.974867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jx4r-qc68-xjr5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2002-20001</id>
    <title>gsd-2002-20001</title>
    <updated>2026-10-02T10:30:44.974885+00:00</updated>
    <content>gsd-2002-20001</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2002-20001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-314-10</id>
    <title>ICSA-22-314-10 — Siemens SCALANCE W1750D</title>
    <updated>2026-10-02T10:30:44.974896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE. (ATLWL-266) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-253) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-254) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-299) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-300) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending spec…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-314-10"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11905-1</id>
    <title>openSUSE-SU-2024:11905-1 — libopenssl-1_1-devel-1.1.1m-4.1 on GA media</title>
    <updated>2026-10-02T10:30:44.974956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-1_1-devel-1.1.1m-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11905-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-001</id>
    <title>VDE-2023-001 — PHOENIX CONTACT: Multiple Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T10:30:44.975000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A new LTS Firmware release fixes known vulnerabilities in used open-source libraries.
In addition, the following improvements have been implemented:
HMI
- Hardening against DoS attacks. - Hardening against memory leak problems in case of network attacks.
WBM
- Umlauts in the password of the 'User Manager' were not handled correctly. The password rule for upper and lower case was not followed. This could lead to unintentionally weaker passwords.- Hardening of WBM against Cross-Site-Scripting.
User Manager
- In security notifications 'SecurityToken' was always displayed as '0000000' when creating or modifying users.- Hardening of Trust and Identity Stores.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-017</id>
    <title>VDE-2024-017 — Pepperl+Fuchs: ICE2- * and ICE3- * are affected by multiple vulnerabilities</title>
    <updated>2026-10-02T10:30:44.975078+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities have been discovered in the product due to outdated software components.The impact of the vulnerabilities on the affected device may result in</p>
<p>Denial of service
Bypassing of authentication
Information disclosure</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2251</id>
    <title>WID-SEC-W-2022-2251 — Aruba ClearPass Policy Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:30:44.975100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Aruba ClearPass Policy Manager ausnutzen, um SQL Injection- und Cross Site Scripting Angriffe durchzuführen, Code zur Ausführung zu bringen, seine Rechte zu erweitern oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2251"/>
  </entry>
</feed>
