<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:34:31.432437+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:9318</id>
    <title>ALSA-2025:9318 — Important: javapackages-tools:201801 security update</title>
    <updated>2026-10-02T11:34:32.022122+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: ant, AlmaLinux:8: ant-antlr, AlmaLinux:8: ant-apache-bcel, AlmaLinux:8: ant-apache-bsf, AlmaLinux:8: ant-apache-log4j, AlmaLinux:8: ant-apache-oro, AlmaLinux:8: ant-apache-regexp, AlmaLinux:8: ant-apache-resolver, AlmaLinux:8: ant-apache-xalan2, AlmaLinux:8: ant-commons-logging and 500 more</p>
<p>The javapackages-tools packages provide macros and scripts to support Java packaging.</p>
<p>Security Fix(es):</p>
<p>* apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)
  * commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default (CVE-2025-48734)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:9318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-01020</id>
    <title>bdu:2020-01020</title>
    <updated>2026-10-02T11:34:32.022755+00:00</updated>
    <content>bdu:2020-01020</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-01020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-433</id>
    <title>certfr-2020-avi-433 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T11:34:32.022780+00:00</updated>
    <content>certfr-2020-avi-433</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-42779</id>
    <title>cnvd-2019-42779</title>
    <updated>2026-10-02T11:34:32.022797+00:00</updated>
    <content>cnvd-2019-42779</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-42779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-53346</id>
    <title>EUVD-2026-53346</title>
    <updated>2026-10-02T11:34:32.022809+00:00</updated>
    <content>EUVD-2026-53346</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-53346"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10086</id>
    <title>fkie_cve-2019-10086</title>
    <updated>2026-10-02T11:34:32.022820+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-10086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6phf-73q6-gh87</id>
    <title>GHSA-6phf-73q6-gh87 — Insecure Deserialization in Apache Commons Beanutils</title>
    <updated>2026-10-02T11:34:32.022843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: commons-beanutils:commons-beanutils</p>
<p>In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6phf-73q6-gh87"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-10086</id>
    <title>gsd-2019-10086</title>
    <updated>2026-10-02T11:34:32.022865+00:00</updated>
    <content>gsd-2019-10086</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-10086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2058-1</id>
    <title>openSUSE-SU-2019:2058-1 — Security update for apache-commons-beanutils</title>
    <updated>2026-10-02T11:34:32.022876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache-commons-beanutils</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:2058-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2020:0496</id>
    <title>RHBA-2020:0496 — Red Hat Bug Fix Advisory: Satellite 6.6.2 Async Bug Fix Update</title>
    <updated>2026-10-02T11:34:32.022894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2020:0496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:2244-1</id>
    <title>SUSE-SU-2019:2244-1 — Security update for apache-commons-beanutils</title>
    <updated>2026-10-02T11:34:32.022910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache-commons-beanutils</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:2244-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10086</id>
    <title>UBUNTU-CVE-2019-10086</title>
    <updated>2026-10-02T11:34:32.022925+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: commons-beanutils, Ubuntu:Pro:16.04:LTS: commons-beanutils, Ubuntu:Pro:18.04:LTS: commons-beanutils</p>
<p>In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</id>
    <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:34:32.022948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770"/>
  </entry>
</feed>
