<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:04:13.001973+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-02137</id>
    <title>bdu:2020-02137</title>
    <updated>2026-10-03T15:04:13.181134+00:00</updated>
    <content>bdu:2020-02137</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-02137"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-433</id>
    <title>certfr-2020-avi-433 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T15:04:13.181184+00:00</updated>
    <content>certfr-2020-avi-433</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-22364</id>
    <title>cnvd-2020-22364</title>
    <updated>2026-10-03T15:04:13.181205+00:00</updated>
    <content>cnvd-2020-22364</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-22364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-195659</id>
    <title>EUVD-2026-195659</title>
    <updated>2026-10-03T15:04:13.181218+00:00</updated>
    <content>EUVD-2026-195659</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-195659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-13990</id>
    <title>fkie_cve-2019-13990</title>
    <updated>2026-10-03T15:04:13.181228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-13990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9qcf-c26r-x5rf</id>
    <title>GHSA-9qcf-c26r-x5rf — XML external entity injection in Terracotta Quartz Scheduler</title>
    <updated>2026-10-03T15:04:13.181256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.quartz-scheduler:quartz</p>
<p>initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9qcf-c26r-x5rf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-13990</id>
    <title>gsd-2019-13990</title>
    <updated>2026-10-03T15:04:13.181300+00:00</updated>
    <content>gsd-2019-13990</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-13990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:3196</id>
    <title>RHSA-2020:3196 — Red Hat Security Advisory: Red Hat Decision Manager 7.8.0 Security Update</title>
    <updated>2026-10-03T15:04:13.181323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth HTTP/2: flood using empty frames results in excessive resource consumption cxf: does not restrict the number of message attachments cxf: OpenId Connect token service does not properly validate the clientId libquartz: XXE attacks via job description netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers cxf: reflected XSS in the services listing page jackson-databind: lacks certain net.sf.ehcache blocking netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header keycloak: security issue on reset credential flow netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProvide…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:3196"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:0984-1</id>
    <title>SUSE-SU-2020:0984-1 — Security update for quartz</title>
    <updated>2026-10-03T15:04:13.181484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for quartz</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:0984-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-13990</id>
    <title>UBUNTU-CVE-2019-13990</title>
    <updated>2026-10-03T15:04:13.181504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: libquartz-java, Ubuntu:18.04:LTS: libquartz-java, Ubuntu:18.04:LTS: libquartz2-java, Ubuntu:20.04:LTS: libquartz-java, Ubuntu:20.04:LTS: libquartz2-java, Ubuntu:22.04:LTS: libquartz-java, Ubuntu:24.04:LTS: libquartz-java, Ubuntu:25.10: libquartz-java, Ubuntu:26.04:LTS: libquartz-java</p>
<p>initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-13990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2700</id>
    <title>WID-SEC-W-2023-2700 — Atlassian Confluence: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:04:13.181536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Atlassian Confluence, Atlassian Jira Software, Atlassian Bitbucket und Atlassian Bamboo ausnutzen, um Administratorrechte zu erlangen, Informationen offenzulegen, beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2700"/>
  </entry>
</feed>
