<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:42:08.228576+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:6542</id>
    <title>ALSA-2022:6542 — Moderate: php:7.4 security update</title>
    <updated>2026-10-02T11:42:08.245085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: apcu-panel, AlmaLinux:8: libzip, AlmaLinux:8: libzip-devel, AlmaLinux:8: libzip-tools, AlmaLinux:8: php, AlmaLinux:8: php-bcmath, AlmaLinux:8: php-cli, AlmaLinux:8: php-common, AlmaLinux:8: php-dba, AlmaLinux:8: php-dbg and 27 more</p>
<p>PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.</p>
<p>Security Fix(es):</p>
<p>* Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocked (CVE-2020-28948)
* Archive_Tar: improper filename sanitization leads to file overwrites (CVE-2020-28949)
* Archive_Tar: directory traversal due to inadequate checking of symbolic links (CVE-2020-36193)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:6542"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03618</id>
    <title>bdu:2021-03618</title>
    <updated>2026-10-02T11:42:08.245203+00:00</updated>
    <content>bdu:2021-03618</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-drupal-2020-28949</id>
    <title>BIT-drupal-2020-28949</title>
    <updated>2026-10-02T11:42:08.245221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: drupal</p>
<p>Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-drupal-2020-28949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-777</id>
    <title>certfr-2020-avi-777 — De multiples vulnérabilités ont été découvertes dans Drupal core. Elles
permettent à un attaquant de provoquer une atte…</title>
    <updated>2026-10-02T11:42:08.245243+00:00</updated>
    <content>certfr-2020-avi-777</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-777"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-zn01309</id>
    <title>CLEANSTART-2024-ZN01309 — Archive_Tar through 1</title>
    <updated>2026-10-02T11:42:08.245271+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: drupal7</p>
<p>Security vulnerability affects the drupal7 package. Archive_Tar through 1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-zn01309"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256050</id>
    <title>EUVD-2026-256050</title>
    <updated>2026-10-02T11:42:08.245318+00:00</updated>
    <content>EUVD-2026-256050</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256050"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-28949</id>
    <title>fkie_cve-2020-28949</title>
    <updated>2026-10-02T11:42:08.245344+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-28949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202302</id>
    <title>FSA-202302 — Festo: Several vulnerabilities in FactoryViews</title>
    <updated>2026-10-02T11:42:08.245365+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>FactoryViews bundles many third-party applications which are used in background processes to provide the software's features. From time to time, vulnerabilities in these bundled applications are discovered. These are typically fixed in newer versions of FactoryViews by updating the bundled applications.</p>
<p>FactoryViews versions up to and including 1.5.2 contain around 200 such vulnerabilities listed in this advisory.Version 1.6.0 is a security rollup release which includes updates to all bundled applications and fixes these vulnerabilities.</p>
<p>At this time, FactoryViews Lite cannot be updated beyond version 1.1. FactoryViews 1.7 unifies the non-Lite and Lite versions and fixes these vulnerabilities for users of FactoryViews Lite.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202302"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-75c5-f4gw-38r9</id>
    <title>GHSA-75c5-f4gw-38r9 — Multiple vulnerabilities through filename manipulation in Archive_Tar</title>
    <updated>2026-10-02T11:42:08.245469+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: pear/archive_tar</p>
<p>Archive_Tar through 1.4.10 has `://` filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as `file://` to overwrite files) can still succeed. See: https://github.com/pear/Archive_Tar/issues/33</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-75c5-f4gw-38r9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-28949</id>
    <title>gsd-2020-28949</title>
    <updated>2026-10-02T11:42:08.245488+00:00</updated>
    <content>gsd-2020-28949</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-28949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6541</id>
    <title>RHSA-2022:6541 — Red Hat Security Advisory: php:7.4 security update</title>
    <updated>2026-10-02T11:42:08.245499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocked Archive_Tar: improper filename sanitization leads to file overwrites Archive_Tar: directory traversal due to inadequate checking of symbolic links</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6542</id>
    <title>RHSA-2022:6542 — Red Hat Security Advisory: php:7.4 security update</title>
    <updated>2026-10-02T11:42:08.245516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocked Archive_Tar: improper filename sanitization leads to file overwrites Archive_Tar: directory traversal due to inadequate checking of symbolic links</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6542"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-28949</id>
    <title>UBUNTU-CVE-2020-28949</title>
    <updated>2026-10-02T11:42:08.245531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: drupal7, Ubuntu:16.04:LTS: php-pear, Ubuntu:Pro:16.04:LTS: drupal7, Ubuntu:18.04:LTS: php-pear, Ubuntu:20.04:LTS: php-pear</p>
<p>Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-28949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1443</id>
    <title>WID-SEC-W-2022-1443 — Drupal: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes</title>
    <updated>2026-10-02T11:42:08.245554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Drupal ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1443"/>
  </entry>
</feed>
