<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:52:22.433569+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-06642</id>
    <title>cnvd-2017-06642</title>
    <updated>2026-10-03T03:52:22.499685+00:00</updated>
    <content>cnvd-2017-06642</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-06642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-178815</id>
    <title>EUVD-2026-178815</title>
    <updated>2026-10-03T03:52:22.499719+00:00</updated>
    <content>EUVD-2026-178815</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-178815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-6812</id>
    <title>fkie_cve-2016-6812</title>
    <updated>2026-10-03T03:52:22.499734+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-6812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vw2c-5wph-v92r</id>
    <title>GHSA-vw2c-5wph-v92r — Improper Neutralization of Input During Web Page Generation in Apache CXF</title>
    <updated>2026-10-03T03:52:22.499775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.cxf:cxf-core</p>
<p>The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vw2c-5wph-v92r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-6812</id>
    <title>gsd-2016-6812</title>
    <updated>2026-10-03T03:52:22.499803+00:00</updated>
    <content>gsd-2016-6812</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-6812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2017:0868</id>
    <title>RHSA-2017:0868 — Red Hat Security Advisory: Red Hat JBoss Fuse/A-MQ 6.3 R2 security and bug fix update</title>
    <updated>2026-10-03T03:52:22.499815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name elasticsearch: remote code execution via Groovy sandbox bypass ActiveMQ: DoS in client via shutdown command apache-cxf: XSS in Apache CXF FormattedServiceListWriter Groovy: Remote code execution via deserialization apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE Spark: Directory traversal vulnerability in version 2.5 swagger-ui: cross-site scripting in key names camel-snakeyaml: Unmarshalling operation is vulnerable to RCE</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2017:0868"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</id>
    <title>WID-SEC-W-2026-0180 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:52:22.499841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180"/>
  </entry>
</feed>
