<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:34:06.683972+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-solr-2021-33813</id>
    <title>BIT-solr-2021-33813</title>
    <updated>2026-10-03T19:34:06.971953+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: solr</p>
<p>An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-solr-2021-33813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-386</id>
    <title>certfr-2022-avi-386 — De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM.
Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-03T19:34:06.972008+00:00</updated>
    <content>certfr-2022-avi-386</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-28598</id>
    <title>EUVD-2026-28598</title>
    <updated>2026-10-03T19:34:06.972029+00:00</updated>
    <content>EUVD-2026-28598</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-28598"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-33813</id>
    <title>fkie_cve-2021-33813</title>
    <updated>2026-10-03T19:34:06.972041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-33813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2363-cqg2-863c</id>
    <title>GHSA-2363-cqg2-863c — XML External Entity (XXE) Injection in JDOM</title>
    <updated>2026-10-03T19:34:06.972062+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jdom:jdom2, Maven: org.jdom:jdom</p>
<p>An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. As a workaround, to avoid external entities being expanded, one can call `builder.setExpandEntities(false)` and they won't be expanded.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2363-cqg2-863c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-33813</id>
    <title>gsd-2021-33813</title>
    <updated>2026-10-03T19:34:06.972086+00:00</updated>
    <content>gsd-2021-33813</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-33813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1630</id>
    <title>OESA-2022-1630 — jdom2 security update</title>
    <updated>2026-10-03T19:34:06.972098+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: jdom2, openEuler:20.03-LTS-SP3: jdom2, openEuler:22.03-LTS: jdom2</p>
<p>JDOM is an in-memory representation of an XML document. XML consists of elements (which have attributes), text data, 'entity' references, processing instructions, and comments. XML documents can also have a DocType declaration, Comments, and Processing Instructions before the root element.

Security Fix(es):

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.(CVE-2021-33813)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1031-1</id>
    <title>openSUSE-SU-2021:1031-1 — Security update for jdom2</title>
    <updated>2026-10-03T19:34:06.972123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jdom2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1031-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:1029</id>
    <title>RHSA-2022:1029 — Red Hat Security Advisory: Red Hat Integration Camel-K 1.6.4 release and security update</title>
    <updated>2026-10-03T19:34:06.972140+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>guava: local information disclosure via temporary directory created with unsafe permissions bouncycastle: Timing issue within the EC math library jetty: buffer not correctly recycled in Gzip Request inflation undertow: buffer leak on incoming websocket PONG message may lead to DoS RESTEasy: PathParam in RESTEasy can lead to a reflected XSS attack XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host maven: Block repositories using http by default jersey: Local information disclosure via system temporary directory jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate jdom: XXE allows attackers to cause a DoS via a crafted HTTP request cyrus-sasl: failure to properly escape SQL input allows an attacker to execute arbitrary SQL commands</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:1029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:2293-1</id>
    <title>SUSE-SU-2021:2293-1 — Security update for jdom2</title>
    <updated>2026-10-03T19:34:06.972173+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jdom2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:2293-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33813</id>
    <title>UBUNTU-CVE-2021-33813</title>
    <updated>2026-10-03T19:34:06.972189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: libjdom1-java, Ubuntu:16.04:LTS: libjdom1-java, Ubuntu:16.04:LTS: libjdom2-java, Ubuntu:18.04:LTS: libjdom1-java, Ubuntu:18.04:LTS: libjdom2-java, Ubuntu:20.04:LTS: libjdom1-java, Ubuntu:20.04:LTS: libjdom2-java, Ubuntu:22.04:LTS: libjdom1-java, Ubuntu:22.04:LTS: libjdom2-java, Ubuntu:24.04:LTS: libjdom1-java and 5 more</p>
<p>An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</id>
    <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:34:06.972222+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607"/>
  </entry>
</feed>
