<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:11:23.418148+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-04661</id>
    <title>cnvd-2020-04661</title>
    <updated>2026-10-03T06:11:23.527480+00:00</updated>
    <content>cnvd-2020-04661</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-04661"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-35568</id>
    <title>EUVD-2026-35568</title>
    <updated>2026-10-03T06:11:23.527518+00:00</updated>
    <content>EUVD-2026-35568</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-35568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1697</id>
    <title>fkie_cve-2020-1697</title>
    <updated>2026-10-03T06:11:23.527532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-1697"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8vf3-4w62-m3pq</id>
    <title>GHSA-8vf3-4w62-m3pq — XSS in Keycloak</title>
    <updated>2026-10-03T06:11:23.527564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-core</p>
<p>It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8vf3-4w62-m3pq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-1697</id>
    <title>gsd-2020-1697</title>
    <updated>2026-10-03T06:11:23.527588+00:00</updated>
    <content>gsd-2020-1697</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-1697"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:0445</id>
    <title>RHSA-2020:0445 — Red Hat Security Advisory: Red Hat Single Sign-On 7.3.6 security update</title>
    <updated>2026-10-03T06:11:23.527600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xstream: remote code execution due to insecure XML deserialization (regression of  CVE-2013-7285) hibernate-validator: safeHTML validator allows XSS jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS jackson-databind: Serialization gadgets in classes of the commons-configuration package jackson-databind: Serialization gadgets in classes of the xalan package jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in classes of the ehcache package jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.* keycloak: stored XSS in client settings via application links</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:0445"/>
  </entry>
</feed>
