<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:44:12.303419+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2016-avi-075</id>
    <title>certfr-2016-avi-075 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Ruby On Rails&lt;/span&gt;. Elles permettent à un att…</title>
    <updated>2026-10-02T14:44:12.316126+00:00</updated>
    <content>certfr-2016-avi-075</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2016-avi-075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-01678</id>
    <title>cnvd-2016-01678</title>
    <updated>2026-10-02T14:44:12.316167+00:00</updated>
    <content>cnvd-2016-01678</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-01678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-82806</id>
    <title>EUVD-2026-82806</title>
    <updated>2026-10-02T14:44:12.316183+00:00</updated>
    <content>EUVD-2026-82806</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-82806"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-2098</id>
    <title>fkie_cve-2016-2098</title>
    <updated>2026-10-02T14:44:12.316194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-2098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-78rc-8c29-p45g</id>
    <title>GHSA-78rc-8c29-p45g — actionpack allows remote code execution via application's unrestricted use of render method</title>
    <updated>2026-10-02T14:44:12.316221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionpack</p>
<p>Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-78rc-8c29-p45g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-2098</id>
    <title>gsd-2016-2098</title>
    <updated>2026-10-02T14:44:12.316246+00:00</updated>
    <content>gsd-2016-2098</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-2098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10057-1</id>
    <title>openSUSE-SU-2024:10057-1 — ruby2.2-rubygem-actionview-4_2-4.2.7.1-1.1 on GA media</title>
    <updated>2026-10-02T14:44:12.316257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby2.2-rubygem-actionview-4_2-4.2.7.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10057-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:0454</id>
    <title>RHSA-2016:0454 — Red Hat Security Advisory: ror40 security update</title>
    <updated>2026-10-02T14:44:12.316274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller rubygem-activerecord: Nested attributes rejection proc bypass in Active Record rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack rubygem-actionpack: possible object leak and denial of service attack in Action Pack rubygem-actionpack: directory traversal flaw in Action View rubygem-actionpack: directory traversal in Action View, incomplete CVE-2016-0752 fix rubygem-actionpack: code injection vulnerability in Action View</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:0454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2016:0854-1</id>
    <title>SUSE-SU-2016:0854-1 — Security update for rubygem-actionview-4_1</title>
    <updated>2026-10-02T14:44:12.316299+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-actionview-4_1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2016:0854-1"/>
  </entry>
</feed>
