<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:08:31.279785+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03510</id>
    <title>bdu:2021-03510</title>
    <updated>2026-10-02T16:08:31.777759+00:00</updated>
    <content>bdu:2021-03510</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-8286</id>
    <title>Withdrawn: BELL-CVE-2020-8286 — CVE-2020-8286 does not affect BellSoft software</title>
    <updated>2026-10-02T16:08:31.777812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-8286"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-314</id>
    <title>certfr-2021-avi-314 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
    <updated>2026-10-02T16:08:31.777844+00:00</updated>
    <content>certfr-2021-avi-314</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</id>
    <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
    <updated>2026-10-02T16:08:31.777860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: curl</p>
<p>Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-40504</id>
    <title>cnvd-2021-40504</title>
    <updated>2026-10-02T16:08:31.777902+00:00</updated>
    <content>cnvd-2021-40504</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-40504"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-201770</id>
    <title>EUVD-2026-201770</title>
    <updated>2026-10-02T16:08:31.777917+00:00</updated>
    <content>EUVD-2026-201770</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-201770"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8286</id>
    <title>fkie_cve-2020-8286</title>
    <updated>2026-10-02T16:08:31.777929+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-8286"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xh5x-q49r-r9w4</id>
    <title>GHSA-xh5x-q49r-r9w4</title>
    <updated>2026-10-02T16:08:31.777952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xh5x-q49r-r9w4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-8286</id>
    <title>gsd-2020-8286</title>
    <updated>2026-10-02T16:08:31.777966+00:00</updated>
    <content>gsd-2020-8286</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-8286"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-159-10</id>
    <title>ICSA-21-159-10 — Siemens SIMATIC TIM libcurl</title>
    <updated>2026-10-02T16:08:31.777977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The libcurl library versions 7.62.0 to and including 7.70.0 are vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). The libcurl library versions 7.41.0 to and including 7.73.0 are vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. This vulnerability could allow an attacker to pass a revoked certificate as valid.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-159-10"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-8286</id>
    <title>msrc_CVE-2020-8286 — curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verificati…</title>
    <updated>2026-10-02T16:08:31.777999+00:00</updated>
    <content>msrc_CVE-2020-8286</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-8286"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1004</id>
    <title>OESA-2021-1004 — curl security update</title>
    <updated>2026-10-02T16:08:31.778015+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS: curl, openEuler:20.03-LTS-SP1: curl</p>
<p>cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.\r\n\r\n
Security Fix(es):\r\n\r\n
Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.(CVE-2020-8231)\r\n\r\n
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.(CVE-2020-8286)\r\n\r\n
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.(CVE-2020-8285)\r\n\r\n
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.(CVE-2020-8284)\r\n\r\n</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:2238-1</id>
    <title>openSUSE-SU-2020:2238-1 — Security update for curl</title>
    <updated>2026-10-02T16:08:31.778043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:2238-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:2471</id>
    <title>RHSA-2021:2471 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP8 security update</title>
    <updated>2026-10-02T16:08:31.778061+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libcurl: partial password leak over DNS on HTTP redirect curl: FTP PASV command response can cause curl to connect to arbitrary host curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used curl: Inferior OCSP verification curl: Leak of authentication credentials in URL via automatic Referer curl: TLS 1.3 session ticket mix-up with HTTPS proxy host curl: Use-after-free in TLS session handling when using OpenSSL TLS backend</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:2471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:3733-1</id>
    <title>SUSE-SU-2020:3733-1 — Security update for curl</title>
    <updated>2026-10-02T16:08:31.778087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:3733-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8286</id>
    <title>UBUNTU-CVE-2020-8286</title>
    <updated>2026-10-02T16:08:31.778104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: curl, Ubuntu:18.04:LTS: curl, Ubuntu:20.04:LTS: curl</p>
<p>curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8286"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-019</id>
    <title>VDE-2022-019 — Endress+Hauser: Multiple products utilizing vulnerable WIBU-SYSTEMS CodeMeter components</title>
    <updated>2026-10-02T16:08:31.778125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1350</id>
    <title>WID-SEC-W-2023-1350 — Splunk Splunk Enterprise: Mehrere Schwachstellen in Komponenten von Drittanbietern</title>
    <updated>2026-10-02T16:08:31.778144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise in diversen Komponenten von Drittanbietern ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1350"/>
  </entry>
</feed>
