<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:00:30.160451+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03074</id>
    <title>bdu:2023-03074</title>
    <updated>2026-10-03T10:00:30.253355+00:00</updated>
    <content>bdu:2023-03074</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03074"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-19561</id>
    <title>cnvd-2020-19561</title>
    <updated>2026-10-03T10:00:30.253390+00:00</updated>
    <content>cnvd-2020-19561</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-19561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-59062</id>
    <title>EUVD-2026-59062</title>
    <updated>2026-10-03T10:00:30.253404+00:00</updated>
    <content>EUVD-2026-59062</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-59062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-19090</id>
    <title>fkie_cve-2019-19090</title>
    <updated>2026-10-03T10:00:30.253416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-19090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w59j-v3f8-jgj6</id>
    <title>GHSA-w59j-v3f8-jgj6</title>
    <updated>2026-10-03T10:00:30.253444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w59j-v3f8-jgj6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-19090</id>
    <title>gsd-2019-19090</title>
    <updated>2026-10-03T10:00:30.253460+00:00</updated>
    <content>gsd-2019-19090</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-19090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-20-072-01</id>
    <title>ICSA-20-072-01 — ICSA-20-072-01_ABB eSOMS</title>
    <updated>2026-10-03T10:00:30.253470+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>For ABB eSOMS 6.0.3 and earlier, The Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.CVE-2019-19000 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). For ABB eSOMS Versions 6.0.2 and earlier, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious website, revealing sensitive user information such as authentication credentials. CVE-2019-19001 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). For ABB eSOMS Versions 6.0.2 and earlier, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of cross-site scripting. CVE-2019-19002 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N). For ABB eSOMS Versions 6.0.2 and earlier, the HTTPOnly flag is not set. This can allow JavaScript to access the cookie contents, which in turn might enable Cross-site Scripting. CVE-2019-19003 has been assigned to this vul…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-20-072-01"/>
  </entry>
</feed>
