<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T21:18:50.019179+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-774</id>
    <title>certfr-2021-avi-774 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-10T21:18:50.023824+00:00</updated>
    <content>certfr-2021-avi-774</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-774"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-77589</id>
    <title>cnvd-2021-77589</title>
    <updated>2026-10-10T21:18:50.023861+00:00</updated>
    <content>cnvd-2021-77589</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-77589"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-28575</id>
    <title>EUVD-2026-28575</title>
    <updated>2026-10-10T21:18:50.023877+00:00</updated>
    <content>EUVD-2026-28575</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-28575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-33732</id>
    <title>fkie_cve-2021-33732</title>
    <updated>2026-10-10T21:18:50.023889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been identified in SINEC NMS (All versions &lt; V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-33732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v7wh-pf74-7qcc</id>
    <title>GHSA-v7wh-pf74-7qcc</title>
    <updated>2026-10-10T21:18:50.023916+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been identified in SINEC NMS (All versions &lt; V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v7wh-pf74-7qcc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-33732</id>
    <title>gsd-2021-33732</title>
    <updated>2026-10-10T21:18:50.023933+00:00</updated>
    <content>gsd-2021-33732</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-33732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-287-05</id>
    <title>ICSA-21-287-05 — Siemens SINEC NMS</title>
    <updated>2026-10-10T21:18:50.023943+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The affected system has a Path Traversal vulnerability when exporting a firmware container. With this a privileged authenticated attacker could create arbitrary files on an affected system. An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the affected system. The affected system contains an Arbitrary File Deletion vulnerability that possibly allows to delete an arbitrary file or directory under a user controlled path. The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory. The affected system allows to download arbitrary files under a user controlled path and does not correctly check if the relative path is still within the intended target directory. An authenticated attacker could download the user profile of any user. With this, the attacker could leak confidential information of any user in the affected system. The affected system allows to upload JSON objects that are deserialized to JAVA objects. Due to insecure deserialization of user-supplied content by the affected software, a privileged attacker could exploit this vulnerability by sending a crafted serialized Java object.</p>
<p>An exploit could allow the attacker to execute arbitrary code on the device with root privileges. An authenticated attacker that is able to import f…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-287-05"/>
  </entry>
</feed>
