<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:58:01.549910+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-00881</id>
    <title>bdu:2023-00881</title>
    <updated>2026-10-02T14:58:01.556446+00:00</updated>
    <content>bdu:2023-00881</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-00881"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-221450</id>
    <title>EUVD-2026-221450</title>
    <updated>2026-10-02T14:58:01.556489+00:00</updated>
    <content>EUVD-2026-221450</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-221450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-45138</id>
    <title>fkie_cve-2022-45138</title>
    <updated>2026-10-02T14:58:01.556510+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-45138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hq37-597p-8qrg</id>
    <title>GHSA-hq37-597p-8qrg</title>
    <updated>2026-10-02T14:58:01.556550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hq37-597p-8qrg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-45138</id>
    <title>gsd-2022-45138</title>
    <updated>2026-10-02T14:58:01.556574+00:00</updated>
    <content>gsd-2022-45138</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-45138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-060</id>
    <title>VDE-2022-060 — WAGO: Multiple vulnerabilities in web-based management of multiple products</title>
    <updated>2026-10-02T14:58:01.556592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.
The configuration backend can in some cases be used without authentication and to write data with root privileges. Additionally, the web-based management suffers a CORS misconfiguration and allows reflected XSS (Cross-Site Scripting) attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-060"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-054</id>
    <title>VDE-2024-054 — Endress+Hauser: Netilion Network Insights is affected by multiple vulnerabilities</title>
    <updated>2026-10-02T14:58:01.556624+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several vulnerabilities have been identified in the web-based management of WAGO devices utilized in
Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been
integrated into the solutions by Endress+Hauser. Additionally, a guideline on secure operation of these
solutions has been made available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-054"/>
  </entry>
</feed>
