<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:02:27.547798+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-07236</id>
    <title>bdu:2022-07236</title>
    <updated>2026-10-03T11:02:27.671388+00:00</updated>
    <content>bdu:2022-07236</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-07236"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-86391</id>
    <title>cnvd-2022-86391</title>
    <updated>2026-10-03T11:02:27.671423+00:00</updated>
    <content>cnvd-2022-86391</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-86391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-32242</id>
    <title>EUVD-2026-32242</title>
    <updated>2026-10-03T11:02:27.671439+00:00</updated>
    <content>EUVD-2026-32242</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-32242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-42797</id>
    <title>fkie_cve-2021-42797</title>
    <updated>2026-10-03T11:02:27.671452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-42797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4wwr-56pj-4v9h</id>
    <title>GHSA-4wwr-56pj-4v9h</title>
    <updated>2026-10-03T11:02:27.671479+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4wwr-56pj-4v9h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-42797</id>
    <title>gsd-2021-42797</title>
    <updated>2026-10-03T11:02:27.671495+00:00</updated>
    <content>gsd-2021-42797</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-42797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-326-01</id>
    <title>ICSA-22-326-01 — AVEVA Edge</title>
    <updated>2026-10-03T11:02:27.671506+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In AVEVA Edge versions R2020 and prior could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking the AVEVA Edge InstallShield package to load an unsafe DLL. This attack is only possible during the installation or when performing an install or repair operation.CVE-2016-2542 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). AVEVA Edge versions R2020 and prior could allow internal network scanning and expose sensitive device information.CVE-2021-42794 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). AVEVA Edge versions R2020 and prior could allow unauthenticated arbitrary commands to be executed with the security context of the StADOSvr.exe process. In most instances, this will be a standard-privileged user account under which the AVEVA Edge runtime was started. It's possible for a high-privileged service account to have been configured and assigned for running AVEVA Edge runtime.CVE-2021-42796 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). AVEVA Edge versions R2020 and prior could allow an unauthenticated actor to trick the AVEVA Edge runtime into disclosing a Windows access token of the…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-326-01"/>
  </entry>
</feed>
