<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T17:42:03.164230+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-670</id>
    <title>certfr-2021-avi-670 — De multiples vulnérabilités ont été découvertes dans les produits
Elastic. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-04T17:42:03.240703+00:00</updated>
    <content>certfr-2021-avi-670</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-235623</id>
    <title>EUVD-2026-235623</title>
    <updated>2026-10-04T17:42:03.240748+00:00</updated>
    <content>EUVD-2026-235623</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-235623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-37936</id>
    <title>fkie_cve-2021-37936</title>
    <updated>2026-10-04T17:42:03.240763+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-37936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p8x3-m7c8-mcj5</id>
    <title>GHSA-p8x3-m7c8-mcj5</title>
    <updated>2026-10-04T17:42:03.240791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML, it would be rendered for the user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p8x3-m7c8-mcj5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-37936</id>
    <title>gsd-2021-37936</title>
    <updated>2026-10-04T17:42:03.240807+00:00</updated>
    <content>gsd-2021-37936</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-37936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0029</id>
    <title>WID-SEC-W-2022-0029 — Elasticsearch und Kibana: Mehrere Schwachstellen</title>
    <updated>2026-10-04T17:42:03.240818+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Elasticsearch und Kibana ausnutzen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen und um Administratorrechte zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0029"/>
  </entry>
</feed>
