<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:58:25.830774+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03150</id>
    <title>bdu:2021-03150</title>
    <updated>2026-10-02T12:58:25.910633+00:00</updated>
    <content>bdu:2021-03150</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-37670</id>
    <title>cnvd-2021-37670</title>
    <updated>2026-10-02T12:58:25.910674+00:00</updated>
    <content>cnvd-2021-37670</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-37670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-26722</id>
    <title>EUVD-2026-26722</title>
    <updated>2026-10-02T12:58:25.910690+00:00</updated>
    <content>EUVD-2026-26722</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-26722"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-30192</id>
    <title>fkie_cve-2021-30192</title>
    <updated>2026-10-02T12:58:25.910703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-30192"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m8j4-8jwg-mc3j</id>
    <title>GHSA-m8j4-8jwg-mc3j</title>
    <updated>2026-10-02T12:58:25.910734+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m8j4-8jwg-mc3j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-30192</id>
    <title>gsd-2021-30192</title>
    <updated>2026-10-02T12:58:25.910750+00:00</updated>
    <content>gsd-2021-30192</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-30192"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-173-02</id>
    <title>ICSA-21-173-02 — CODESYS V2 web server</title>
    <updated>2026-10-02T12:58:25.910761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Crafted web server requests may cause a stack-based buffer overflow. This could allow an attacker to execute arbitrary code on the CODESYS web server or trigger a denial-of-service condition due to a crash in the CODESYS web server.CVE-2021-30189 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The user management of the CODESYS v2.3 WebVisu allows user dependent control of access to the visualization pages. However, subordinate requests to read or write values are forwarded to the CODESYS Control runtime system regardless of successful authentication. This enables crafted web server requests to bypass user management and read or write values on the PLC without authentication.CVE-2021-30190 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Crafted web server requests can cause an over-read or over-write of a buffer in the CODESYS web server, which typically leads to a denial-of-service condition.CVE-2021-30191 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Crafted web server requests can bypass the security checks for boot project-related files on the CODESYS Control runtime system and be uploaded from the CODESYS Control runtime system.CVE-2021-30192 has been a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-173-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-014</id>
    <title>VDE-2021-014 — WAGO: Multiple Vulnerabilities in CODESYS Runtime 2.3</title>
    <updated>2026-10-02T12:58:25.910798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities were reported in CODESYS 2.3 Runtime. The CODESYS 2.3 Runtime is an essential component in several WAGO PLC's.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-014"/>
  </entry>
</feed>
