<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T15:25:45.551452+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-05545</id>
    <title>bdu:2020-05545</title>
    <updated>2026-10-07T15:25:45.557277+00:00</updated>
    <content>bdu:2020-05545</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-05545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-drupal-2020-13671</id>
    <title>BIT-drupal-2020-13671</title>
    <updated>2026-10-07T15:25:45.557316+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: drupal</p>
<p>Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-drupal-2020-13671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-760</id>
    <title>certfr-2020-avi-760 — Une vulnérabilité a été découverte dans Drupal Core. Elle permet à un
attaquant de provoquer une exécution de code arbi…</title>
    <updated>2026-10-07T15:25:45.557352+00:00</updated>
    <content>certfr-2020-avi-760</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-760"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-64563</id>
    <title>cnvd-2020-64563</title>
    <updated>2026-10-07T15:25:45.557370+00:00</updated>
    <content>cnvd-2020-64563</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-64563"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256049</id>
    <title>EUVD-2026-256049</title>
    <updated>2026-10-07T15:25:45.557383+00:00</updated>
    <content>EUVD-2026-256049</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13671</id>
    <title>fkie_cve-2020-13671</title>
    <updated>2026-10-07T15:25:45.557393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-13671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-68jc-v27h-vhmw</id>
    <title>GHSA-68jc-v27h-vhmw — Drupal core Unrestricted Upload of File with Dangerous Type</title>
    <updated>2026-10-07T15:25:45.557415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: drupal/core, Packagist: drupal/drupal</p>
<p>Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-68jc-v27h-vhmw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-13671</id>
    <title>gsd-2020-13671</title>
    <updated>2026-10-07T15:25:45.557441+00:00</updated>
    <content>gsd-2020-13671</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-13671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13671</id>
    <title>UBUNTU-CVE-2020-13671</title>
    <updated>2026-10-07T15:25:45.557452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: drupal7, Ubuntu:Pro:16.04:LTS: drupal7</p>
<p>Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1938</id>
    <title>WID-SEC-W-2024-1938 — Drupal: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes</title>
    <updated>2026-10-07T15:25:45.557472+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Drupal ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1938"/>
  </entry>
</feed>
