<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T14:26:22.745399+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253150</id>
    <title>EUVD-2026-253150</title>
    <updated>2026-10-07T14:26:22.748682+00:00</updated>
    <content>EUVD-2026-253150</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0773</id>
    <title>fkie_cve-2014-0773</title>
    <updated>2026-10-07T14:26:22.748713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The BWOCXRUN.BwocxrunCtrl.1 control contains a method named 
“CreateProcess.” This method contains validation to ensure an attacker 
cannot run arbitrary command lines. After validation, the values 
supplied in the HTML are passed to the Windows CreateProcessA API.</p>
<p>The validation can be bypassed allowing for running arbitrary command
 lines. The command line can specify running remote files (example: UNC 
command line).</p>
<p>A function exists at offset 100019B0 of bwocxrun.ocx. Inside this 
function, there are 3 calls to strstr to check the contents of the user 
specified command line. If “\setup.exe,” “\bwvbprt.exe,” or 
“\bwvbprtl.exe” are contained in the command line (strstr returns 
nonzero value), the command line passes validation and is then passed to
 CreateProcessA.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-0773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wc8h-x86j-g2mp</id>
    <title>GHSA-wc8h-x86j-g2mp</title>
    <updated>2026-10-07T14:26:22.748754+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to execute (1) setup.exe, (2) bwvbprt.exe, and (3) bwvbprtl.exe programs from arbitrary pathnames via a crafted argument, as demonstrated by a UNC share pathname.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wc8h-x86j-g2mp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-0773</id>
    <title>gsd-2014-0773</title>
    <updated>2026-10-07T14:26:22.748773+00:00</updated>
    <content>gsd-2014-0773</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-0773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-14-079-03</id>
    <title>ICSA-14-079-03 — Advantech WebAccess Vulnerabilities</title>
    <updated>2026-10-07T14:26:22.748785+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple SQL injection vulnerabilities in DBVisitor.dll in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary SQL commands via SOAP requests to unspecified functions. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName parameter. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long GotoCmd argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long NodeName2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long AccessCode2 argument. Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long UserName parameter. The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The OpenUrlToBufferTimeout method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL. The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-14-079-03"/>
  </entry>
</feed>
