<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:29:19.181576+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-01050</id>
    <title>bdu:2021-01050</title>
    <updated>2026-10-03T06:29:19.191559+00:00</updated>
    <content>bdu:2021-01050</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-01050"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-090</id>
    <title>certfr-2022-avi-090 — De multiples vulnérabilités ont été découvertes dans Foxit PDF Reader et
Foxit PDF Editor. Certaines d'entre elles perm…</title>
    <updated>2026-10-03T06:29:19.191591+00:00</updated>
    <content>certfr-2022-avi-090</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-32847</id>
    <title>cnvd-2020-32847</title>
    <updated>2026-10-03T06:29:19.191609+00:00</updated>
    <content>cnvd-2020-32847</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-32847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-61121</id>
    <title>EUVD-2026-61121</title>
    <updated>2026-10-03T06:29:19.191621+00:00</updated>
    <content>EUVD-2026-61121</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-61121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1285</id>
    <title>fkie_cve-2018-1285</title>
    <updated>2026-10-03T06:29:19.191631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-1285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2cwj-8chv-9pp9</id>
    <title>GHSA-2cwj-8chv-9pp9 — XML External Entity attack in log4net</title>
    <updated>2026-10-03T06:29:19.191656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: log4net</p>
<p>Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2cwj-8chv-9pp9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-1285</id>
    <title>gsd-2018-1285</title>
    <updated>2026-10-03T06:29:19.191677+00:00</updated>
    <content>gsd-2018-1285</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-1285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-226-02</id>
    <title>ICSA-24-226-02 — Rockwell Automation AADvance Standalone OPC-DA Server</title>
    <updated>2026-10-03T06:29:19.191687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An arbitrary code execution vulnerability exists in the affected product. The log4net config file does not disable XML external entities.  An arbitrary code execution vulnerability exists in the affected product. The vulnerability occurs due to a vulnerable component, the format string in log4net.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-226-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12311-1</id>
    <title>openSUSE-SU-2024:12311-1 — log4net-1.2.10-78.1 on GA media</title>
    <updated>2026-10-03T06:29:19.191704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>log4net-1.2.10-78.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12311-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1285</id>
    <title>UBUNTU-CVE-2018-1285</title>
    <updated>2026-10-03T06:29:19.191718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: log4net, Ubuntu:18.04:LTS: log4net, Ubuntu:20.04:LTS: log4net, Ubuntu:22.04:LTS: log4net</p>
<p>Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-041</id>
    <title>VDE-2021-041 — Pepperl+Fuchs: Multiple DTM and VisuNet Software affected by log4net vulnerability</title>
    <updated>2026-10-03T06:29:19.191739+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities have been discovered in the utilized component log4net by Apache Software Foundation.</p>
<p>UPDATE A: Remediation: added fixed VisuNet Products</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-004</id>
    <title>VDE-2024-004 — TRUMPF: Multiple products affected by log4net vulnerability</title>
    <updated>2026-10-03T06:29:19.191755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-004"/>
  </entry>
</feed>
