<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:15:48.897070+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-06637</id>
    <title>bdu:2022-06637</title>
    <updated>2026-10-03T07:15:49.034085+00:00</updated>
    <content>bdu:2022-06637</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-06637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-99359</id>
    <title>EUVD-2026-99359</title>
    <updated>2026-10-03T07:15:49.034123+00:00</updated>
    <content>EUVD-2026-99359</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-99359"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-3623</id>
    <title>fkie_cve-2014-3623</title>
    <updated>2026-10-03T07:15:49.034136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-3623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-99v3-9x35-c5vf</id>
    <title>GHSA-99v3-9x35-c5vf — Improper Authentication in Apache WSS4J</title>
    <updated>2026-10-03T07:15:49.034165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.ws.security:wss4j, Maven: org.apache.wss4j:wss4j-ws-security-dom</p>
<p>Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-99v3-9x35-c5vf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-3623</id>
    <title>gsd-2014-3623</title>
    <updated>2026-10-03T07:15:49.034190+00:00</updated>
    <content>gsd-2014-3623</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-3623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2014:2019</id>
    <title>RHSA-2014:2019 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.3.2 security update</title>
    <updated>2026-10-03T07:15:49.034202+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix CXF: Improper security semantics enforcement of SAML SubjectConfirmation methods</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2014:2019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</id>
    <title>WID-SEC-W-2022-1375 — JFrog Artifactory: Mehrere Schwachstellen</title>
    <updated>2026-10-03T07:15:49.034222+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375"/>
  </entry>
</feed>
