<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:30:22.011004+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00276</id>
    <title>bdu:2022-00276</title>
    <updated>2026-10-04T04:30:22.203901+00:00</updated>
    <content>bdu:2022-00276</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-556</id>
    <title>certfr-2021-avi-556 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-04T04:30:22.203942+00:00</updated>
    <content>certfr-2021-avi-556</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-14153</id>
    <title>cnvd-2021-14153</title>
    <updated>2026-10-04T04:30:22.203961+00:00</updated>
    <content>cnvd-2021-14153</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-14153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-41003</id>
    <title>EUVD-2026-41003</title>
    <updated>2026-10-04T04:30:22.203973+00:00</updated>
    <content>EUVD-2026-41003</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-41003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11988</id>
    <title>fkie_cve-2020-11988</title>
    <updated>2026-10-04T04:30:22.203984+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-11988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fmj2-7wx8-qj4v</id>
    <title>GHSA-fmj2-7wx8-qj4v — Server-side request forgery (SSRF) in Apache XmlGraphics Commons</title>
    <updated>2026-10-04T04:30:22.204012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.xmlgraphics:xmlgraphics-commons</p>
<p>Apache XmlGraphics Commons 2.4 is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fmj2-7wx8-qj4v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-11988</id>
    <title>gsd-2020-11988</title>
    <updated>2026-10-04T04:30:22.204035+00:00</updated>
    <content>gsd-2020-11988</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-11988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1649</id>
    <title>OESA-2022-1649 — xmlgraphics-commons security update</title>
    <updated>2026-10-04T04:30:22.204046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: xmlgraphics-commons, openEuler:20.03-LTS-SP3: xmlgraphics-commons, openEuler:22.03-LTS: xmlgraphics-commons</p>
<p>Apache XML Graphics Commons is a library that consists of several reusable components used by Apache Batik and Apache FOP. Many of these components can easily be used separately outside the domains of SVG and XSL-FO. You will find components such as a PDF library, an RTF library, Graphics2D implementations that let you generate PDF and PostScript files, and much more. The Apache™ XML Graphics Commons project is part of the Apache™ Software Foundation, which is a wider community of users and developers of open source projects.

Security Fix(es):

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.(CVE-2020-11988)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12403-1</id>
    <title>openSUSE-SU-2024:12403-1 — xmlgraphics-commons-2.6-3.1 on GA media</title>
    <updated>2026-10-04T04:30:22.204079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xmlgraphics-commons-2.6-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12403-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:2475</id>
    <title>RHSA-2021:2475 — Red Hat Security Advisory: Red Hat Process Automation Manager 7.11.0 security update</title>
    <updated>2026-10-04T04:30:22.204097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xmlgraphics-commons: SSRF due to improper input validation by the XMPParser jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling XStream: arbitrary file deletion on the local host when unmarshalling XStream: allow a remote attacker to cause DoS only by manipulating the processed input stream XStream: SSRF via crafted input stream XStream: arbitrary file deletion on the local host via crafted input stream XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator XStream: ReDoS vulnerability XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host XStream: Unsafe deserizaliation of com.sun.org.apache.bcel.internal.util.ClassLoader XStream: allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:2475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3550-1</id>
    <title>SUSE-SU-2022:3550-1 — Security update for xmlgraphics-commons</title>
    <updated>2026-10-04T04:30:22.204139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for xmlgraphics-commons</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3550-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11988</id>
    <title>UBUNTU-CVE-2020-11988</title>
    <updated>2026-10-04T04:30:22.204154+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: xmlgraphics-commons, Ubuntu:18.04:LTS: xmlgraphics-commons, Ubuntu:20.04:LTS: xmlgraphics-commons, Ubuntu:22.04:LTS: xmlgraphics-commons, Ubuntu:24.04:LTS: xmlgraphics-commons, Ubuntu:25.10: xmlgraphics-commons, Ubuntu:26.04:LTS: xmlgraphics-commons</p>
<p>Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1017</id>
    <title>WID-SEC-W-2023-1017 — Oracle Financial Services Applications: Mehrere Schwachstellen</title>
    <updated>2026-10-04T04:30:22.204183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1017"/>
  </entry>
</feed>
