<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:20:23.955969+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-11088</id>
    <title>cnvd-2016-11088</title>
    <updated>2026-10-02T22:20:24.992081+00:00</updated>
    <content>cnvd-2016-11088</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-11088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-86416</id>
    <title>EUVD-2026-86416</title>
    <updated>2026-10-02T22:20:24.992116+00:00</updated>
    <content>EUVD-2026-86416</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-86416"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-7077</id>
    <title>fkie_cve-2016-7077</title>
    <updated>2026-10-02T22:20:24.992131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-7077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qw4f-j9p2-3626</id>
    <title>GHSA-qw4f-j9p2-3626</title>
    <updated>2026-10-02T22:20:24.992158+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qw4f-j9p2-3626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-7077</id>
    <title>gsd-2016-7077</title>
    <updated>2026-10-02T22:20:24.992174+00:00</updated>
    <content>gsd-2016-7077</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-7077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:0336</id>
    <title>RHSA-2018:0336 — Red Hat Security Advisory: Satellite 6.3 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T22:20:24.992185+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-will_paginate: XSS vulnerabilities foreman: models with a 'belongs_to' association to an Organization do not verify association belongs to that Organization V8: integer overflow leading to buffer overflow in Zone::New foreman: inspect in a provisioning template exposes sensitive controller information pulp: Leakage of CA key in pulp-qpid-ssl-cfg pulp: Unsafe use of bash $RANDOM for NSS DB password and seed foreman: privilege escalation through Organization and Locations API foreman: Information disclosure in provisioning template previews foreman: inside discovery-debug, the root password is displayed in plaintext foreman: Persistent XSS in Foreman remote execution plugin foreman: Foreman information leak through unauthorized multiple_checkboxes helper foreman: Information leak through organizations and locations feature foreman: Stored XSS vulnerability in remote execution plugin foreman: Stored XSS in org/loc wizard foreman: Stored XSS via organization/location with HTML in name foreman-debug: missing obfuscation of sensitive information katello-debug: Possible symlink attacks due to use of predictable file names puppet: Unsafe YAML deserialization rubygem-hammer_cli: no verification of API server's SSL certificate foreman: Image password leak Interconnect: Denial of Service vulnerability in Red Hat JBoss AMQ Interconnect katello: SQL inject in errata-related REST API</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:0336"/>
  </entry>
</feed>
