<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:03:16.350093+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2015-01339</id>
    <title>cnvd-2015-01339</title>
    <updated>2026-10-03T03:03:16.416341+00:00</updated>
    <content>cnvd-2015-01339</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2015-01339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-102989</id>
    <title>EUVD-2026-102989</title>
    <updated>2026-10-03T03:03:16.416377+00:00</updated>
    <content>EUVD-2026-102989</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-102989"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-8114</id>
    <title>fkie_cve-2014-8114</title>
    <updated>2026-10-03T03:03:16.416391+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-8114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6h58-c7r7-g2hw</id>
    <title>GHSA-6h58-c7r7-g2hw — UberFire Framework Improperly Restricts Paths</title>
    <updated>2026-10-03T03:03:16.416418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.uberfire:uberfire-parent</p>
<p>The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6h58-c7r7-g2hw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-8114</id>
    <title>gsd-2014-8114</title>
    <updated>2026-10-03T03:03:16.416440+00:00</updated>
    <content>gsd-2014-8114</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-8114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2015:0234</id>
    <title>RHSA-2015:0234 — Red Hat Security Advisory: Red Hat JBoss BPM Suite 6.0.3 security update</title>
    <updated>2026-10-03T03:03:16.416451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CXF: SSL hostname verification bypass, incomplete CVE-2012-5783 fix OpenJDK: XML parsing Denial of Service (JAXP, 8017298) JSF: XSS due to insufficient escaping of user-supplied content in outputText tags and EL expressions PicketBox/JBossSX: Unauthorized access to and modification of application server configuration and state by application Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter Tomcat/JBossWeb: XXE vulnerability via user supplied XSLTs Tomcat/JBossWeb: Request smuggling via malicious content length header Tomcat/JBossWeb: XML parser hijack by malicious web application netty: DoS via memory exhaustion during data aggregation Tomcat/JBossWeb: request smuggling and limited DoS in ChunkedInputFilter Security: Invalid EJB caller role check implementation RESTEasy: XXE via parameter entities PicketLink: XXE via insecure DocumentBuilderFactory usage Validator: JSM bypass via ReflectionHelper CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix Framework: Directory traversal Framework: directory traversal flaw jbpm-designer: XXE in BPMN2 import UberFire: Information disclosure and RCE via insecure file upload/download servlets Workbench: Insufficient authorization constraints</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2015:0234"/>
  </entry>
</feed>
