<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T12:58:02.889893+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-17312</id>
    <title>cnvd-2019-17312</title>
    <updated>2026-10-09T12:58:02.893905+00:00</updated>
    <content>cnvd-2019-17312</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-17312"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-52637</id>
    <title>EUVD-2026-52637</title>
    <updated>2026-10-09T12:58:02.893940+00:00</updated>
    <content>EUVD-2026-52637</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-52637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-9189</id>
    <title>fkie_cve-2019-9189</title>
    <updated>2026-10-09T12:58:02.893955+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-9189"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-36c5-5h9q-3jvp</id>
    <title>GHSA-36c5-5h9q-3jvp</title>
    <updated>2026-10-09T12:58:02.893983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On Prima Systems FlexAir devices through 2.4.9api3, an authenticated user can upload Python (.py) scripts and execute arbitrary code with root privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-36c5-5h9q-3jvp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-9189</id>
    <title>gsd-2019-9189</title>
    <updated>2026-10-09T12:58:02.893999+00:00</updated>
    <content>gsd-2019-9189</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-9189"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-19-211-02</id>
    <title>ICSA-19-211-02 — Prima Systems FlexAir</title>
    <updated>2026-10-09T12:58:02.894010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.CVE-2019-7670 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application 's web root with root privileges.CVE-2019-7669 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.CVE-2019-7281 has been assigned to this vulnerability. A CVSS v3 base score of 5.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L). The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.CVE-2019-7280 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Parameters sent to scripts are not…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-19-211-02"/>
  </entry>
</feed>
