<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:30:28.001244+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-08522</id>
    <title>bdu:2023-08522</title>
    <updated>2026-10-03T17:30:28.068549+00:00</updated>
    <content>bdu:2023-08522</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-08522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-210916</id>
    <title>EUVD-2026-210916</title>
    <updated>2026-10-03T17:30:28.068586+00:00</updated>
    <content>EUVD-2026-210916</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-210916"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-27394</id>
    <title>fkie_cve-2023-27394</title>
    <updated>2026-10-03T17:30:28.068600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-27394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w554-444w-32f7</id>
    <title>GHSA-w554-444w-32f7</title>
    <updated>2026-10-03T17:30:28.068631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w554-444w-32f7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-27394</id>
    <title>gsd-2023-27394</title>
    <updated>2026-10-03T17:30:28.068647+00:00</updated>
    <content>gsd-2023-27394</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-27394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-082-06</id>
    <title>ICSA-23-082-06 — ProPump and Controls Osprey Pump Controller (Update A)</title>
    <updated>2026-10-03T17:30:28.068658+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Osprey Pump Controller versions prior to release 20230518 are vulnerable to a predictable weak session token generation algorithm and could aid in authentication and authorization bypass. This could allow a cyber threat actor to hijack a session by predicting the session ID and gain unauthorized access to the product. Osprey Pump Controller versions prior to release 20230518 are vulnerable to an unauthenticated file disclosure. Cyber threat actors could use a GET parameter to force the affected device to disclose arbitrary files and sensitive system information. Osprey Pump Controller versions prior to release 20230518 have a hidden administrative account with a hardcoded password that allows full access to the web management interface configuration. The account is not visible in the Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation of the device. Osprey Pump Controller versions prior to release 20230518 are vulnerable to an unauthenticated OS command injection vulnerability. Threat actors could exploit this vulnerability to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script. Osprey Pump Controller versions prior to release 20230518 are vulnerable an unauthenticated OS command injection vulnerability. Threat actors could exploit this vulnerability to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-082-06"/>
  </entry>
</feed>
