<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:31:16.427499+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2015-00729</id>
    <title>bdu:2015-00729</title>
    <updated>2026-10-02T20:31:16.729979+00:00</updated>
    <content>bdu:2015-00729</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2015-00729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2014-avi-319</id>
    <title>certfr-2014-avi-319 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Oracle Retail&lt;/span&gt;. Elles permettent à un att…</title>
    <updated>2026-10-02T20:31:16.730019+00:00</updated>
    <content>certfr-2014-avi-319</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2014-avi-319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-96717</id>
    <title>EUVD-2026-96717</title>
    <updated>2026-10-02T20:31:16.730038+00:00</updated>
    <content>EUVD-2026-96717</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-96717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0114</id>
    <title>fkie_cve-2014-0114</title>
    <updated>2026-10-02T20:31:16.730050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-0114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p66x-2cv9-qq3v</id>
    <title>GHSA-p66x-2cv9-qq3v — Arbitrary code execution in Apache Commons BeanUtils</title>
    <updated>2026-10-02T20:31:16.730081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: commons-beanutils:commons-beanutils</p>
<p>Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p66x-2cv9-qq3v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-0114</id>
    <title>gsd-2014-0114</title>
    <updated>2026-10-02T20:31:16.730107+00:00</updated>
    <content>gsd-2014-0114</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-0114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsma-20-184-01</id>
    <title>ICSMA-20-184-01 — OpenClinic GA (Update B)</title>
    <updated>2026-10-02T20:31:16.730119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An attacker may bypass client-side access controls or use a crafted request to initiate a session with limited functionality, which may allow execution of admin functions such as SQL queries.CVE-2020-14485 has been assigned to this vulnerability. A CVSS v3 base score of 9.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). An attacker can bypass the system 's account lockout protection, which may allow brute force password attacks.CVE-2020-14484 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). An authentication mechanism within the system does not contain sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts.CVE-2020-14494 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). The system does not properly check permissions before executing SQL queries, which may allow a low-privilege user to access privileged information.CVE-2020-14491 has been assigned to this vulnerability. A CVSS v3 base score of 8.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L). A low-privilege user may use SQL syntax to write arbitrary files to the server, which may allow the execution of arbitrary commands.CVE-…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsma-20-184-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2014-000056</id>
    <title>jvndb-2014-000056</title>
    <updated>2026-10-02T20:31:16.730166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TERASOLUNA Server Framework for Java(Web) provided by NTT DATA Corporation is a software framework for creating Java web applications. TERASOLUNA Server Framework for Java(Web) bundles Apache Struts 1.2.9, which contains a vulnerability where the ClassLoader may be manipulated (CVE-2014-0114). Therefore, this vulnerability affects TERASOLUNA Server Framework for Java(Web) as well.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2014-000056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10617-1</id>
    <title>openSUSE-SU-2024:10617-1 — apache-commons-beanutils-1.9.4-3.7 on GA media</title>
    <updated>2026-10-02T20:31:16.730185+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache-commons-beanutils-1.9.4-3.7 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10617-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2014:0474</id>
    <title>RHSA-2014:0474 — Red Hat Security Advisory: struts security update</title>
    <updated>2026-10-02T20:31:16.730203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>1: Class Loader manipulation via request parameters</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2014:0474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2015:0611-1</id>
    <title>SUSE-RU-2015:0611-1 — Recommended update for SUSE Manager Server 2.1</title>
    <updated>2026-10-02T20:31:16.730217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for SUSE Manager Server 2.1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2015:0611-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0114</id>
    <title>UBUNTU-CVE-2014-0114</title>
    <updated>2026-10-02T20:31:16.730234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: commons-beanutils, Ubuntu:Pro:16.04:LTS: commons-beanutils, Ubuntu:Pro:18.04:LTS: commons-beanutils</p>
<p>Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-0114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</id>
    <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:31:16.730258+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770"/>
  </entry>
</feed>
