<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T23:06:10.615046+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-139977</id>
    <title>EUVD-2026-139977</title>
    <updated>2026-10-07T23:06:10.688373+00:00</updated>
    <content>EUVD-2026-139977</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-139977"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2006-1548</id>
    <title>fkie_cve-2006-1548</title>
    <updated>2026-10-07T23:06:10.688412+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2006-1548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p3vw-fvwx-qcv5</id>
    <title>GHSA-p3vw-fvwx-qcv5 — Cross-site scripting in Apache Struts</title>
    <updated>2026-10-07T23:06:10.688445+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: struts:struts</p>
<p>Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p3vw-fvwx-qcv5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2006-1548</id>
    <title>gsd-2006-1548</title>
    <updated>2026-10-07T23:06:10.688471+00:00</updated>
    <content>gsd-2006-1548</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2006-1548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2006:0281</id>
    <title>RHSA-2006:0281 — Red Hat Security Advisory: struts security update for Red Hat Application Server</title>
    <updated>2026-10-07T23:06:10.688493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>struts bypass validation security flaw struts LookupDispatchAction XSS</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2006:0281"/>
  </entry>
</feed>
