<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:00:33.780484+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-10589</id>
    <title>cnvd-2016-10589</title>
    <updated>2026-10-05T22:00:33.786634+00:00</updated>
    <content>cnvd-2016-10589</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-10589"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-87561</id>
    <title>EUVD-2026-87561</title>
    <updated>2026-10-05T22:00:33.786670+00:00</updated>
    <content>EUVD-2026-87561</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-87561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-9013</id>
    <title>fkie_cve-2016-9013</title>
    <updated>2026-10-05T22:00:33.786684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-9013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mv8g-fhh6-6267</id>
    <title>GHSA-mv8g-fhh6-6267 — Django user with hardcoded password created when running tests on Oracle</title>
    <updated>2026-10-05T22:00:33.786713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Django</p>
<p>Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mv8g-fhh6-6267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-9013</id>
    <title>gsd-2016-9013</title>
    <updated>2026-10-05T22:00:33.786738+00:00</updated>
    <content>gsd-2016-9013</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-9013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2016-17</id>
    <title>PYSEC-2016-17</title>
    <updated>2026-10-05T22:00:33.786749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: django</p>
<p>Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2016-17"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:0973-1</id>
    <title>SUSE-SU-2018:0973-1 — Security update for python-Django</title>
    <updated>2026-10-05T22:00:33.786766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Django</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:0973-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-9013</id>
    <title>UBUNTU-CVE-2016-9013</title>
    <updated>2026-10-05T22:00:33.786783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: python-django, Ubuntu:16.04:LTS: python-django</p>
<p>Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-9013"/>
  </entry>
</feed>
