<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:52:27.531868+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-04685</id>
    <title>bdu:2023-04685</title>
    <updated>2026-10-02T10:52:27.632112+00:00</updated>
    <content>bdu:2023-04685</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-04685"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0525</id>
    <title>certfr-2023-avi-0525 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
    <updated>2026-10-02T10:52:27.632169+00:00</updated>
    <content>certfr-2023-avi-0525</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-220705</id>
    <title>EUVD-2026-220705</title>
    <updated>2026-10-02T10:52:27.632191+00:00</updated>
    <content>EUVD-2026-220705</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-220705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-47379</id>
    <title>fkie_cve-2022-47379</title>
    <updated>2026-10-02T10:52:27.632204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-47379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202401</id>
    <title>FSA-202401 — Festo: Multiple products contain CoDe16 vulnerability</title>
    <updated>2026-10-02T10:52:27.632235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several high severity vulnerabilities in CODESYS V3 affecting Festo products could lead to Remote Code Execution or Denial of Service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202401"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3339-3jp2-pq45</id>
    <title>GHSA-3339-3jp2-pq45</title>
    <updated>2026-10-02T10:52:27.632265+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3339-3jp2-pq45"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-47379</id>
    <title>gsd-2022-47379</title>
    <updated>2026-10-02T10:52:27.632280+00:00</updated>
    <content>gsd-2022-47379</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-47379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-030-07</id>
    <title>ICSA-24-030-07 — Rockwell Automation LP30/40/50 and BM40 Operator Interface</title>
    <updated>2026-10-02T10:52:27.632291+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>After successful authentication, specifically crafted communication requests with inconsistent content can cause the CmpFiletransfer component to read internally from an invalid address, potentially leading to a denial-of-service condition.  After successful authentication, specifically crafted communication requests can cause the CmpApp component to write threat actor-controlled data to memory, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpApp component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpApp component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpTraceMgr component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpTraceMgr component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote cod…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-030-07"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2023-192-04</id>
    <title>SEVD-2023-192-04 — CODESYS Runtime Vulnerabilities</title>
    <updated>2026-10-02T10:52:27.632337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities disclosed on CODESYS runtime system V3 communication server. Many vendors, including Schneider Electric, embed CODESYS in their offers. 

If successfully exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 / LMC058 / LMC078 / M218 ,  HMISCU, the Simulation Runtime SoftSPS from EcoStruxure Machine Expert and EcoStruxure Microgrid Operation products. 

Failure to apply the mitigations provided below may result in denial of service and/or arbitrary remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2023-192-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-026</id>
    <title>VDE-2023-026 — WAGO: Multiple products prone to multiple vulnerabilities in e!Runtime / CODESYS V3 Runtime</title>
    <updated>2026-10-02T10:52:27.632381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple WAGO devices are prone to vulnerabilites in the used CODESYS V3 framework.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-026"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-003</id>
    <title>VDE-2026-003 — Endress+Hauser: Multiple products prone to multiple vulnerabilities in e!Runtime and CODESYS V3 Runtime</title>
    <updated>2026-10-02T10:52:27.632406+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple Endress+Hauser devices are prone to vulnerabilities found in e!Runtime and the CODESYS V3 framework.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2270</id>
    <title>WID-SEC-W-2023-2270 — Codesys V3: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:52:27.632430+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Codesys V3 ausnutzen, um beliebigen Programmcode auszuführen, Speicher zu überschreiben oder einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2270"/>
  </entry>
</feed>
