<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:07:27.070241+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-01021</id>
    <title>bdu:2020-01021</title>
    <updated>2026-10-02T15:07:27.353957+00:00</updated>
    <content>bdu:2020-01021</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-01021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-034</id>
    <title>certfr-2020-avi-034 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T15:07:27.354001+00:00</updated>
    <content>certfr-2020-avi-034</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-48403</id>
    <title>EUVD-2026-48403</title>
    <updated>2026-10-02T15:07:27.354021+00:00</updated>
    <content>EUVD-2026-48403</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-48403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-0221</id>
    <title>fkie_cve-2019-0221</title>
    <updated>2026-10-02T15:07:27.354033+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-0221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jjpq-gp5q-8q6w</id>
    <title>GHSA-jjpq-gp5q-8q6w — Cross-site scripting in Apache Tomcat</title>
    <updated>2026-10-02T15:07:27.354060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat:tomcat</p>
<p>The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jjpq-gp5q-8q6w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-0221</id>
    <title>gsd-2019-0221</title>
    <updated>2026-10-02T15:07:27.354091+00:00</updated>
    <content>gsd-2019-0221</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-0221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1673-1</id>
    <title>openSUSE-SU-2019:1673-1 — Security update for tomcat</title>
    <updated>2026-10-02T15:07:27.354102+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:1673-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:3929</id>
    <title>RHSA-2019:3929 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.2 security release</title>
    <updated>2026-10-02T15:07:27.354120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) tomcat: Apache Tomcat HTTP/2 DoS tomcat: XSS in SSI printenv tomcat: Remote Code Execution on Windows openssl: 0-byte record padding oracle tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:3929"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:1693-1</id>
    <title>SUSE-SU-2019:1693-1 — Security update for tomcat</title>
    <updated>2026-10-02T15:07:27.354145+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:1693-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0221</id>
    <title>UBUNTU-CVE-2019-0221</title>
    <updated>2026-10-02T15:07:27.354159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat8, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat7</p>
<p>The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1994</id>
    <title>WID-SEC-W-2023-1994 — Apache Tomcat: Schwachstelle ermöglicht Cross-Site Scripting</title>
    <updated>2026-10-02T15:07:27.354185+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1994"/>
  </entry>
</feed>
