<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:44:05.064335+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-41186</id>
    <title>cnvd-2020-41186</title>
    <updated>2026-10-03T23:44:05.257456+00:00</updated>
    <content>cnvd-2020-41186</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-41186"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-35578</id>
    <title>EUVD-2026-35578</title>
    <updated>2026-10-03T23:44:05.257497+00:00</updated>
    <content>EUVD-2026-35578</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-35578"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1714</id>
    <title>fkie_cve-2020-1714</title>
    <updated>2026-10-03T23:44:05.257511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-1714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m6mm-q862-j366</id>
    <title>GHSA-m6mm-q862-j366 — Improper Input Validation in Keycloak</title>
    <updated>2026-10-03T23:44:05.257541+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-core, Maven: org.keycloak:keycloak-common</p>
<p>A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m6mm-q862-j366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-1714</id>
    <title>gsd-2020-1714</title>
    <updated>2026-10-03T23:44:05.257595+00:00</updated>
    <content>gsd-2020-1714</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-1714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:2813</id>
    <title>RHSA-2020:2813 — Red Hat Security Advisory: Red Hat Single Sign-On 7.4.1 security update</title>
    <updated>2026-10-03T23:44:05.257623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak: verify-token-audience support is missing in the NodeJS adapter keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core undertow: invalid HTTP request with large chunk size keycloak: top-level navigations to data URLs resulting in XSS are possible (incomplete fix of CVE-2020-1697) jackson-databind: Serialization gadgets in javax.swing.JEditorPane jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &lt;option&gt; tag in HTML passed to DOM manipulation methods</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:2813"/>
  </entry>
</feed>
