<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T23:49:57.490571+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-14232</id>
    <title>cnvd-2020-14232</title>
    <updated>2026-10-04T23:49:57.498837+00:00</updated>
    <content>cnvd-2020-14232</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-14232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256144</id>
    <title>EUVD-2026-256144</title>
    <updated>2026-10-04T23:49:57.498875+00:00</updated>
    <content>EUVD-2026-256144</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256144"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-18988</id>
    <title>fkie_cve-2019-18988</title>
    <updated>2026-10-04T23:49:57.498889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.43148, and used it for at least OptionsPasswordAES in the current version of the product. If an attacker were to know this key, they could decrypt protect information stored in the registry or configuration files of TeamViewer. With versions before v9.x , this allowed for attackers to decrypt the Unattended Access password to the system (which allows for remote login to the system as well as headless file browsing). The latest version still uses the same key for OptionPasswordAES but appears to have changed how the Unattended Access password is stored. While in most cases an attacker requires an existing session on a system, if the registry/configuration keys were stored off of the machine (such as in a file share or online), an attacker could then decrypt the required password to login to the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-18988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-98mp-frx2-qv94</id>
    <title>GHSA-98mp-frx2-qv94</title>
    <updated>2026-10-04T23:49:57.498926+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.43148, and used it for at least OptionsPasswordAES in the current version of the product. If an attacker were to know this key, they could decrypt protect information stored in the registry or configuration files of TeamViewer. With versions before v9.x , this allowed for attackers to decrypt the Unattended Access password to the system (which allows for remote login to the system as well as headless file browsing). The latest version still uses the same key for OptionPasswordAES but appears to have changed how the Unattended Access password is stored. While in most cases an attacker requires an existing session on a system, if the registry/configuration keys were stored off of the machine (such as in a file share or online), an attacker could then decrypt the required password to login to the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-98mp-frx2-qv94"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-18988</id>
    <title>gsd-2019-18988</title>
    <updated>2026-10-04T23:49:57.498948+00:00</updated>
    <content>gsd-2019-18988</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-18988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-308-01</id>
    <title>ICSA-21-308-01 — VISAM VBASE Editor</title>
    <updated>2026-10-04T23:49:57.498960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected product is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.CVE-2021-38417has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). The affected product does not neutralize or incorrectly neutralizes user-controllable input before the data is placed in output used as a public-facing webpage.CVE-2021-42535 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N). The affected software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.CVE-2021-42537 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N). The affected product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy. The following CVEs are associated with this product.CVE-2021-34803, CVE-2020-13699, CVE-2019-18988, CVE-2018-16550, CVE-2018-14333, CVE-2005-2475 have been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:L/A…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-308-01"/>
  </entry>
</feed>
