<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:58:30.924408+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-66135</id>
    <title>EUVD-2026-66135</title>
    <updated>2026-10-02T21:58:31.007902+00:00</updated>
    <content>EUVD-2026-66135</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-66135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-12981</id>
    <title>fkie_cve-2018-12981</title>
    <updated>2026-10-02T21:58:31.007942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browser.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-12981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vjxp-m6h5-h384</id>
    <title>GHSA-vjxp-m6h5-h384</title>
    <updated>2026-10-02T21:58:31.007980+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browser.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vjxp-m6h5-h384"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-12981</id>
    <title>gsd-2018-12981</title>
    <updated>2026-10-02T21:58:31.008000+00:00</updated>
    <content>gsd-2018-12981</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-12981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-18-198-02</id>
    <title>ICSA-18-198-02 — WAGO e!DISPLAY Web-Based-Management</title>
    <updated>2026-10-02T21:58:31.008013+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Authenticated and unauthenticated users can send specially crafted requests to the web server, which allows code injection within the WBM. The code will be rendered and/or executed within the user 's browser.CVE-2018-12981 has been assigned to this vulnerability. A CVSS v3 base score of 8.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-18-198-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2018-010</id>
    <title>VDE-2018-010 — WAGO: Multiple vulnerabilities in e!DISPLAY products</title>
    <updated>2026-10-02T21:58:31.008038+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unauthenticated user can exploit a vulnerability (CVE-2018-12981) to inject code in the WBM via reflected cross-site scripting (XSS), if he is able trick a user to open a special crafted web site. This could allow an attacker to execute code in the context of the user and execute arbitrary commands with restriction to the permissions of the user. Authenticated users can use a vulnerability to inject code in the WBM via persistent cross-site scripting (XSS) via special crafted requests which will be rendered and/or executed in the browser. Authenticated WBM users can transfer arbitrary files to different file system locations (CVE- 2018-12980) to which the web server has the required permissions and partially allowing replacing existing files due weak file permissions (CVE-2018-12979) which can result in an authentication bypass.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2018-010"/>
  </entry>
</feed>
