<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T04:51:51.483015+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-182243</id>
    <title>EUVD-2026-182243</title>
    <updated>2026-10-07T04:51:51.595438+00:00</updated>
    <content>EUVD-2026-182243</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-182243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2010-2086</id>
    <title>fkie_cve-2010-2086</title>
    <updated>2026-10-07T04:51:51.595500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2010-2086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-92cv-wv2c-8899</id>
    <title>GHSA-92cv-wv2c-8899 — Apache MyFaces Cross-site Scripting vulnerability</title>
    <updated>2026-10-07T04:51:51.595543+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.myfaces.core:myfaces-core-module</p>
<p>Apache MyFaces 1.1.7 and 1.2.8 (All previous versions are likely vulnerable), as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-92cv-wv2c-8899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2010-2086</id>
    <title>gsd-2010-2086</title>
    <updated>2026-10-07T04:51:51.595602+00:00</updated>
    <content>gsd-2010-2086</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2010-2086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2010:0119</id>
    <title>RHSA-2010:0119 — Red Hat Security Advisory: JBoss Enterprise Web Server 1.0.1 update</title>
    <updated>2026-10-07T04:51:51.595623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: unexpected file deletion and/or alteration tomcat: unexpected file deletion in work directory TLS: MITM attacks via session renegotiation MyFaces: XSS via state view</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2010:0119"/>
  </entry>
</feed>
