<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T23:57:06.133985+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07354</id>
    <title>bdu:2023-07354</title>
    <updated>2026-10-04T23:57:06.650784+00:00</updated>
    <content>bdu:2023-07354</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0047</id>
    <title>certfr-2024-avi-0047 — De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft.
Elles permettent à un attaquant de provoquer un…</title>
    <updated>2026-10-04T23:57:06.650829+00:00</updated>
    <content>certfr-2024-avi-0047</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0047"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258472</id>
    <title>EUVD-2026-258472</title>
    <updated>2026-10-04T23:57:06.650849+00:00</updated>
    <content>EUVD-2026-258472</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-44483</id>
    <title>fkie_cve-2023-44483</title>
    <updated>2026-10-04T23:57:06.650862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-44483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xfrj-6vvc-3xm2</id>
    <title>GHSA-xfrj-6vvc-3xm2 — Apache Santuario - XML Security for Java are vulnerable to private key disclosure</title>
    <updated>2026-10-04T23:57:06.650894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.santuario:xmlsec</p>
<p>All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xfrj-6vvc-3xm2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-44483</id>
    <title>gsd-2023-44483</title>
    <updated>2026-10-04T23:57:06.650922+00:00</updated>
    <content>gsd-2023-44483</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-44483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2380</id>
    <title>OESA-2025-2380 — xml-security security update</title>
    <updated>2026-10-04T23:57:06.650933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: xml-security</p>
<p>The XML Security project is aimed at providing implementation of security standards for XML. Currently the focus is on the W3C standards : - XML-Signature Syntax and Processing; and - XML Encryption Syntax and Processing.

Security Fix(es):</p>
<p>All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.(CVE-2023-44483)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0710</id>
    <title>RHSA-2024:0710 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.15 Security update</title>
    <updated>2026-10-04T23:57:06.650958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jgit: arbitrary file overwrite santuario: Private Key disclosure in debug-log output</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0710"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-44483</id>
    <title>UBUNTU-CVE-2023-44483</title>
    <updated>2026-10-04T23:57:06.650978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: libxml-security-java, Ubuntu:18.04:LTS: libxml-security-java, Ubuntu:20.04:LTS: libxml-security-java, Ubuntu:22.04:LTS: libxml-security-java, Ubuntu:24.04:LTS: libxml-security-java, Ubuntu:25.10: libxml-security-java, Ubuntu:26.04:LTS: libxml-security-java</p>
<p>All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-44483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2943</id>
    <title>WID-SEC-W-2023-2943 — IBM WebSphere Application Server Liberty: Mehrere Schwachstellen ermöglichen die Offenlegung von Informationen</title>
    <updated>2026-10-04T23:57:06.651009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter authentifizierter Angreifer kann mehrere Schwachstellen in IBM WebSphere Application Server Liberty ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2943"/>
  </entry>
</feed>
