<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:04:34.657407+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-cassandra-2020-13946</id>
    <title>BIT-cassandra-2020-13946</title>
    <updated>2026-10-04T07:04:34.662764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: cassandra</p>
<p>In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-cassandra-2020-13946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0537</id>
    <title>certfr-2023-avi-0537 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-04T07:04:34.662814+00:00</updated>
    <content>certfr-2023-avi-0537</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-50259</id>
    <title>cnvd-2020-50259</title>
    <updated>2026-10-04T07:04:34.662835+00:00</updated>
    <content>cnvd-2020-50259</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-50259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42080</id>
    <title>EUVD-2026-42080</title>
    <updated>2026-10-04T07:04:34.662849+00:00</updated>
    <content>EUVD-2026-42080</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42080"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13946</id>
    <title>fkie_cve-2020-13946</title>
    <updated>2026-10-04T07:04:34.662860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-13946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-24ww-mc5x-xc43</id>
    <title>GHSA-24ww-mc5x-xc43 — Man-in-the-middle attack in Apache Cassandra</title>
    <updated>2026-10-04T07:04:34.662882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.cassandra:cassandra-all</p>
<p>In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-24ww-mc5x-xc43"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-13946</id>
    <title>gsd-2020-13946</title>
    <updated>2026-10-04T07:04:34.662906+00:00</updated>
    <content>gsd-2020-13946</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-13946"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0811</id>
    <title>RHSA-2021:0811 — Red Hat Security Advisory: Red Hat Integration Tech-Preview 3 Camel K security update</title>
    <updated>2026-10-04T07:04:34.662917+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cassandra: allows manipulation of the RMI registry to perform a MITM attack and capture user names and passwords used to access the JMX interface apache-httpclient: incorrect handling of malformed authority component in request URIs jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0811"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1737</id>
    <title>WID-SEC-W-2023-1737 — Juniper Patchday Juli 2023</title>
    <updated>2026-10-04T07:04:34.662935+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer oder lokaler Angreifer kann mehrere Schwachstellen in verschiedenen Juniper Produkten ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen und seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1737"/>
  </entry>
</feed>
