<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:07:19.850904+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07372</id>
    <title>bdu:2023-07372</title>
    <updated>2026-10-02T16:07:19.871260+00:00</updated>
    <content>bdu:2023-07372</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07372"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-activemq-2023-46604</id>
    <title>BIT-activemq-2023-46604 — Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to…</title>
    <updated>2026-10-02T16:07:19.871305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: activemq</p>
<p>The Java OpenWire protocol marshaller is vulnerable to Remote Code 
Execution. This vulnerability may allow a remote attacker with network 
access to either a Java-based OpenWire broker or client to run arbitrary
 shell commands by manipulating serialized class types in the OpenWire 
protocol to cause either the client or the broker (respectively) to 
instantiate any class on the classpath.</p>
<p>Users are recommended to upgrade
 both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 
which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-activemq-2023-46604"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0919</id>
    <title>certfr-2023-avi-0919 — Une vulnérabilité a été découverte dans &lt;span class="textit"&gt;les
produits SolarWinds&lt;/span&gt;. Elle permet à un attaquant…</title>
    <updated>2026-10-02T16:07:19.871342+00:00</updated>
    <content>certfr-2023-avi-0919</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0919"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2023-94073</id>
    <title>cnvd-2023-94073</title>
    <updated>2026-10-02T16:07:19.871358+00:00</updated>
    <content>cnvd-2023-94073</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2023-94073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258476</id>
    <title>EUVD-2026-258476</title>
    <updated>2026-10-02T16:07:19.871369+00:00</updated>
    <content>EUVD-2026-258476</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46604</id>
    <title>fkie_cve-2023-46604</title>
    <updated>2026-10-02T16:07:19.871379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The Java OpenWire protocol marshaller is vulnerable to Remote Code 
Execution. This vulnerability may allow a remote attacker with network 
access to either a Java-based OpenWire broker or client to run arbitrary
 shell commands by manipulating serialized class types in the OpenWire 
protocol to cause either the client or the broker (respectively) to 
instantiate any class on the classpath.</p>
<p>Users are recommended to upgrade
 both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 
which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-46604"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-crg9-44h2-xw35</id>
    <title>GHSA-crg9-44h2-xw35 — Apache ActiveMQ is vulnerable to Remote Code Execution</title>
    <updated>2026-10-02T16:07:19.871402+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.activemq:activemq-client, Maven: org.apache.activemq:activemq-openwire-legacy</p>
<p>Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.</p>
<p>Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-crg9-44h2-xw35"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-46604</id>
    <title>gsd-2023-46604</title>
    <updated>2026-10-02T16:07:19.871429+00:00</updated>
    <content>gsd-2023-46604</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-46604"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-130-03</id>
    <title>ICSA-24-130-03 — Delta Electronics InfraSuite Device Master</title>
    <updated>2026-10-02T16:07:19.871440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Delta Electronics InfraSuite Device Master contains a deserialization of untrusted data vulnerability because it runs a version of Apache ActiveMQ (5.15.2) which is vulnerable to CVE-2023-46604.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-130-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1778</id>
    <title>OESA-2023-1778 — activemq security update</title>
    <updated>2026-10-02T16:07:19.871456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: activemq, openEuler:20.03-LTS-SP3: activemq, openEuler:22.03-LTS: activemq, openEuler:22.03-LTS-SP1: activemq, openEuler:22.03-LTS-SP2: activemq</p>
<p>The most popular and powerful open source messaging and Integration Patterns server.

Security Fix(es):

Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. 

Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.(CVE-2023-46604)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oxas-adv-2024-0001</id>
    <title>OXAS-ADV-2024-0001 — OX App Suite Security Advisory OXAS-ADV-2024-0001</title>
    <updated>2026-10-02T16:07:19.871482+00:00</updated>
    <content>OXAS-ADV-2024-0001</content>
    <link href="https://cve.radiocsirt.org/vuln/oxas-adv-2024-0001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:6849</id>
    <title>RHSA-2023:6849 — Red Hat Security Advisory: Red Hat JBoss Fuse/A-MQ Fuse 6.3 R20 HF1 security and bug fix update</title>
    <updated>2026-10-02T16:07:19.871497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:6849"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sca-2024-0001</id>
    <title>SCA-2024-0001 — Vulnerability in SICK Logistics Analytics Products and SICK Field Analytics</title>
    <updated>2026-10-02T16:07:19.871512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both Apache ActiveMQ Classic and Apache ActiveMQ Legacy brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sca-2024-0001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46604</id>
    <title>UBUNTU-CVE-2023-46604</title>
    <updated>2026-10-02T16:07:19.871528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:22.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq</p>
<p>The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary  shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade  both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46604"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2773</id>
    <title>WID-SEC-W-2023-2773 — Apache ActiveMQ: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T16:07:19.871551+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache ActiveMQ ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2773"/>
  </entry>
</feed>
