<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:23:05.884528+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-105611</id>
    <title>EUVD-2026-105611</title>
    <updated>2026-10-02T23:23:05.889112+00:00</updated>
    <content>EUVD-2026-105611</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-105611"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2013-1768</id>
    <title>fkie_cve-2013-1768</title>
    <updated>2026-10-02T23:23:05.889144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2013-1768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j65f-mvgw-prp2</id>
    <title>GHSA-j65f-mvgw-prp2 — Deserialization of Untrusted Data in Apache OpenJPA</title>
    <updated>2026-10-02T23:23:05.889175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.openjpa:openjpa</p>
<p>The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j65f-mvgw-prp2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2013-1768</id>
    <title>gsd-2013-1768</title>
    <updated>2026-10-02T23:23:05.889199+00:00</updated>
    <content>gsd-2013-1768</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2013-1768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2013:1185</id>
    <title>RHSA-2013:1185 — Red Hat Security Advisory: Red Hat JBoss Fuse 6.0.0 patch 2</title>
    <updated>2026-10-02T23:23:05.889210+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-json: Denial of Service and SQL Injection openjpa: Remote arbitrary code execution by creating a serialized object and leveraging improperly secured server programs ruby: entity expansion DoS vulnerability in REXML apache-cxf: Multiple denial of service flaws in the StAX parser</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2013:1185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-1768</id>
    <title>Withdrawn: UBUNTU-CVE-2013-1768</title>
    <updated>2026-10-02T23:23:05.889229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:14.04:LTS: openjpa, Ubuntu:16.04:LTS: openjpa</p>
<p>The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-1768"/>
  </entry>
</feed>
