<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:05:55.700094+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05847</id>
    <title>bdu:2023-05847</title>
    <updated>2026-10-02T13:05:55.703862+00:00</updated>
    <content>bdu:2023-05847</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-239370</id>
    <title>EUVD-2026-239370</title>
    <updated>2026-10-02T13:05:55.703892+00:00</updated>
    <content>EUVD-2026-239370</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-239370"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-29444</id>
    <title>fkie_cve-2023-29444</title>
    <updated>2026-10-02T13:05:55.703906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to gain initial access and code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-29444"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w876-744c-hf5g</id>
    <title>GHSA-w876-744c-hf5g</title>
    <updated>2026-10-02T13:05:55.703934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to gain initial access and code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w876-744c-hf5g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-29444</id>
    <title>gsd-2023-29444</title>
    <updated>2026-10-02T13:05:55.703951+00:00</updated>
    <content>gsd-2023-29444</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-29444"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-243-03</id>
    <title>ICSA-23-243-03 — PTC Kepware KepServerEX (Update A)</title>
    <updated>2026-10-02T13:05:55.703962+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The installer application of KEPServerEX is vulnerable to DLL search order hijacking. This could allow an adversary to repackage the installer with a malicious DLL and trick users into installing the trojanized software. Successful exploitation could lead to code execution with administrator privileges. KEPServerEX binary is vulnerable to DLL search order hijacking. A locally authenticated adversary could escalate privileges to administrator by planting a malicious DLL in a specific directory. KEPServerEx is vulnerable to UNC path injection via a malicious project file. By tricking a user into loading a project file and clicking a specific button in the GUI, an adversary could obtain Windows user NTLMv2 hashes, and crack them offline. The KEPServerEX Configuration web server uses basic authentication to protect user credentials. An adversary could perform a man-in-the-middle (MitM) attack via ARP spoofing to obtain the web server's plaintext credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-243-03"/>
  </entry>
</feed>
