<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:43:12.036047+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-05180</id>
    <title>bdu:2020-05180</title>
    <updated>2026-10-03T20:43:12.193140+00:00</updated>
    <content>bdu:2020-05180</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-05180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-29873</id>
    <title>cnvd-2020-29873</title>
    <updated>2026-10-03T20:43:12.193179+00:00</updated>
    <content>cnvd-2020-29873</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-29873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-35740</id>
    <title>EUVD-2026-35740</title>
    <updated>2026-10-03T20:43:12.193194+00:00</updated>
    <content>EUVD-2026-35740</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-35740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1954</id>
    <title>fkie_cve-2020-1954</title>
    <updated>2026-10-03T20:43:12.193206+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-1954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ffm7-7r8g-77xm</id>
    <title>GHSA-ffm7-7r8g-77xm — Apache CXF JMX Integration is vulnerable to a MITM attack</title>
    <updated>2026-10-03T20:43:12.193248+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.cxf:cxf-rt-management</p>
<p>Apache CXF has the ability to integrate with JMX by registering an `InstrumentationManager` extension with the CXF bus. If the `createMBServerConnectorFactory` property of the default `InstrumentationManagerImpl` is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ffm7-7r8g-77xm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-1954</id>
    <title>gsd-2020-1954</title>
    <updated>2026-10-03T20:43:12.193279+00:00</updated>
    <content>gsd-2020-1954</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-1954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:3585</id>
    <title>RHSA-2020:3585 — Red Hat Security Advisory: EAP Continuous Delivery Technical Preview Release 20 security update</title>
    <updated>2026-10-03T20:43:12.193291+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter jackson-mapper-asl: XML external entity similar to CVE-2016-3720 hibernate: SQL injection issue in Hibernate ORM Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain cxf: JMX integration is vulnerable to a MITM attack Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution dom4j: XML External Entity vulnerability in default SAX parser undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header wildfly-elytron: session fixation when using FORM authentication undertow: invalid HTTP request with large chunk size wildfly: unsafe deserialization in Wildfly Enterprise Java Beans netty: compression/decompression codecs don't enforce limits on buffer allocation sizes</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:3585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</id>
    <title>WID-SEC-W-2026-0180 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:43:12.193329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180"/>
  </entry>
</feed>
