<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:20:21.118271+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-71253</id>
    <title>EUVD-2026-71253</title>
    <updated>2026-10-03T18:20:21.122629+00:00</updated>
    <content>EUVD-2026-71253</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-71253"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000850</id>
    <title>fkie_cve-2018-1000850</title>
    <updated>2026-10-03T18:20:21.122670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8p8g-f9vg-r7xr</id>
    <title>GHSA-8p8g-f9vg-r7xr — Directory Traversal vulnerability in Square Retrofit</title>
    <updated>2026-10-03T18:20:21.122726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.squareup.retrofit2:retrofit</p>
<p>Square Retrofit versions from (including) 2.0 to 2.5.0 (excluding) contain a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter. By manipulating the URL an attacker could add or delete resources otherwise unavailable to her. This attack appears to be exploitable via an encoded path parameter on POST, PUT or DELETE request. This vulnerability appears to have been fixed in 2.5.0 and later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8p8g-f9vg-r7xr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-1000850</id>
    <title>gsd-2018-1000850</title>
    <updated>2026-10-03T18:20:21.122753+00:00</updated>
    <content>gsd-2018-1000850</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-1000850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:3892</id>
    <title>RHSA-2019:3892 — Red Hat Security Advisory: Red Hat Fuse 7.5.0 security update</title>
    <updated>2026-10-03T18:20:21.122767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095) infinispan: deserialization of data in XML and JSON transcoders hadoop: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file tomcat: Host name verification missing in WebSocket client jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis activemq: ActiveMQ Client Missing TLS Hostname Verification tika: Incomplete fix allows for XML entity expansion resulting in denial of service jackson-databind: improper polymorphic deserialization of types from Jodd-db library jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver jackson-databind: arbitrary code execution in slf4j-ext class jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes jackson-databind: exfiltration/XXE in some JDK classes jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class jackson-databind: improper polymorphic deserialization in axis2-transport-jms class jackson-databind: improper polymorphic deserialization in openjpa class jackson-databind: improper polymorphic deserialization in jboss-common-core class retrofit: Directory traversal in RequestBuilder allows manipulation of resources zookeeper: Information disclosure in Apa…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:3892"/>
  </entry>
</feed>
