<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T04:28:59.368101+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-227035</id>
    <title>EUVD-2026-227035</title>
    <updated>2026-10-09T04:28:59.371593+00:00</updated>
    <content>EUVD-2026-227035</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-227035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-22373</id>
    <title>fkie_cve-2023-22373</title>
    <updated>2026-10-09T04:28:59.371625+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-22373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-82gc-754r-48p7</id>
    <title>GHSA-82gc-754r-48p7</title>
    <updated>2026-10-09T04:28:59.371655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-82gc-754r-48p7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-22373</id>
    <title>gsd-2023-22373</title>
    <updated>2026-10-09T04:28:59.371672+00:00</updated>
    <content>gsd-2023-22373</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-22373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-347-03</id>
    <title>ICSA-22-347-03 — Contec CONPROSYS HMI System (CHS)</title>
    <updated>2026-10-09T04:28:59.371684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CONPROSYS HMI System versions 3.4.4 and prior are vulnerable to an OS Command Injection, which could allow an unauthenticated remote attacker to send specially crafted requests that could execute commands on the server. CVE-2022-44456 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). In CONPROSYS HMI System Ver.3.4.5 and prior, user credential information could be altered by a remote unauthenticated attacker. CVE-2023-22331 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, user credentials could be obtained via a machine-in-the-middle attack. CVE-2023-22334 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, an arbitrary script could be executed on the web browser of the administrative user logging into the product. This could result in sensitive information being obtained. CVE-2023-22373 has been assigned to this vulnerability. A CVSS v3 base score of 5.7 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). In CONPROSYS HMI System Ver.3.4.5 and prior, a remote unauthenticated attacker could obtain the server certificate, including the private key of the…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-347-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2022-002779</id>
    <title>jvndb-2022-002779</title>
    <updated>2026-10-09T04:28:59.371716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CONPROSYS HMI System (CHS) provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.
 
  * OS Command Injection (CWE-78) - CVE-2022-44456
  * Use of Default Credentials (CWE-1392) - CVE-2023-22331
  * Use of Password Hash Instead of Password for Authentication (CWE-836) - CVE-2023-22334
  * Cross-site Scripting (CWE-79) - CVE-2023-22373
  * Improper Access Control (CWE-284) - CVE-2023-22339

Floris Hendriks and Jeroen Wijenbergh of Radboud University reported these vulnerabilities to Contec Co., Ltd. and coordinated. Contec Co., Ltd. and JPCERT/CC published respective advisories in order to notify users of its solution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2022-002779"/>
  </entry>
</feed>
