<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T01:47:30.658868+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:6542</id>
    <title>ALSA-2022:6542 — Moderate: php:7.4 security update</title>
    <updated>2026-10-05T01:47:30.941586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: apcu-panel, AlmaLinux:8: libzip, AlmaLinux:8: libzip-devel, AlmaLinux:8: libzip-tools, AlmaLinux:8: php, AlmaLinux:8: php-bcmath, AlmaLinux:8: php-cli, AlmaLinux:8: php-common, AlmaLinux:8: php-dba, AlmaLinux:8: php-dbg and 27 more</p>
<p>PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.</p>
<p>Security Fix(es):</p>
<p>* Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocked (CVE-2020-28948)
* Archive_Tar: improper filename sanitization leads to file overwrites (CVE-2020-28949)
* Archive_Tar: directory traversal due to inadequate checking of symbolic links (CVE-2020-36193)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:6542"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-05279</id>
    <title>bdu:2021-05279</title>
    <updated>2026-10-05T01:47:30.941786+00:00</updated>
    <content>bdu:2021-05279</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-05279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-drupal-2020-36193</id>
    <title>BIT-drupal-2020-36193</title>
    <updated>2026-10-05T01:47:30.941810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: drupal</p>
<p>Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-drupal-2020-36193"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-050</id>
    <title>certfr-2021-avi-050 — Une vulnérabilité a été découverte dans Drupal Core. Elle permet à un
attaquant de provoquer un problème de sécurité no…</title>
    <updated>2026-10-05T01:47:30.941833+00:00</updated>
    <content>certfr-2021-avi-050</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-050"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-di03393</id>
    <title>CLEANSTART-2024-DI03393 — Tar</title>
    <updated>2026-10-05T01:47:30.941849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: drupal7</p>
<p>Security vulnerability affects the drupal7 package. Tar.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-di03393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256035</id>
    <title>EUVD-2026-256035</title>
    <updated>2026-10-05T01:47:30.941868+00:00</updated>
    <content>EUVD-2026-256035</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-36193</id>
    <title>fkie_cve-2020-36193</title>
    <updated>2026-10-05T01:47:30.941879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-36193"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202302</id>
    <title>FSA-202302 — Festo: Several vulnerabilities in FactoryViews</title>
    <updated>2026-10-05T01:47:30.941899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>FactoryViews bundles many third-party applications which are used in background processes to provide the software's features. From time to time, vulnerabilities in these bundled applications are discovered. These are typically fixed in newer versions of FactoryViews by updating the bundled applications.</p>
<p>FactoryViews versions up to and including 1.5.2 contain around 200 such vulnerabilities listed in this advisory.Version 1.6.0 is a security rollup release which includes updates to all bundled applications and fixes these vulnerabilities.</p>
<p>At this time, FactoryViews Lite cannot be updated beyond version 1.1. FactoryViews 1.7 unifies the non-Lite and Lite versions and fixes these vulnerabilities for users of FactoryViews Lite.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202302"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rpw6-9xfx-jvcx</id>
    <title>GHSA-rpw6-9xfx-jvcx — Directory Traversal in Archive_Tar</title>
    <updated>2026-10-05T01:47:30.942014+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: pear/archive_tar</p>
<p>Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.</p>
<p>### :exclamation: Note: 
There was an [initial fix](https://github.com/pear/Archive_Tar/commit/cde460582ff389404b5b3ccb59374e9b389de916) for this vulnerability made in version `1.4.12`. That fix introduced a bug which was [fixed in 1.4.13](https://github.com/pear/Archive_Tar/pull/36). Therefore we have set the first-patched-version to `1.4.13` which the earliest working version that avoids this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rpw6-9xfx-jvcx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-36193</id>
    <title>gsd-2020-36193</title>
    <updated>2026-10-05T01:47:30.942037+00:00</updated>
    <content>gsd-2020-36193</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-36193"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1267-1</id>
    <title>openSUSE-SU-2021:1267-1 — Security update for php7-pear</title>
    <updated>2026-10-05T01:47:30.942049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for php7-pear</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1267-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6541</id>
    <title>RHSA-2022:6541 — Red Hat Security Advisory: php:7.4 security update</title>
    <updated>2026-10-05T01:47:30.942065+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocked Archive_Tar: improper filename sanitization leads to file overwrites Archive_Tar: directory traversal due to inadequate checking of symbolic links</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:2926-1</id>
    <title>SUSE-SU-2021:2926-1 — Security update for php72</title>
    <updated>2026-10-05T01:47:30.942084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for php72</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:2926-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-36193</id>
    <title>UBUNTU-CVE-2020-36193</title>
    <updated>2026-10-05T01:47:30.942099+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: php-pear, Ubuntu:18.04:LTS: php-pear, Ubuntu:20.04:LTS: php-pear</p>
<p>Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-36193"/>
  </entry>
</feed>
