<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:11:19.967298+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-40050</id>
    <title>cnvd-2021-40050</title>
    <updated>2026-10-04T10:11:19.970936+00:00</updated>
    <content>cnvd-2021-40050</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-40050"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-178858</id>
    <title>EUVD-2026-178858</title>
    <updated>2026-10-04T10:11:19.970968+00:00</updated>
    <content>EUVD-2026-178858</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-178858"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-27657</id>
    <title>fkie_cve-2021-27657</title>
    <updated>2026-10-04T10:11:19.970983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-27657"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g3gv-gq3r-m3m6</id>
    <title>GHSA-g3gv-gq3r-m3m6</title>
    <updated>2026-10-04T10:11:19.971012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g3gv-gq3r-m3m6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-27657</id>
    <title>gsd-2021-27657</title>
    <updated>2026-10-04T10:11:19.971028+00:00</updated>
    <content>gsd-2021-27657</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-27657"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-159-01</id>
    <title>ICSA-21-159-01 — Johnson Controls Metasys</title>
    <updated>2026-10-04T10:11:19.971039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Metasys servers, engines, and tools do not properly assign, modify, track, or check privileges for an actor, thus creating an unintended sphere of control for said actor. CVE-2021-27657 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-159-01"/>
  </entry>
</feed>
