<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:40:01.566714+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-08854</id>
    <title>bdu:2024-08854</title>
    <updated>2026-10-03T20:40:01.571448+00:00</updated>
    <content>bdu:2024-08854</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-08854"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-fmc-sql-inj-loyafcfq</id>
    <title>cisco-sa-fmc-sql-inj-LOYAFcfq — Cisco Secure Firewall Management Center Software SQL Injection Vulnerabilities</title>
    <updated>2026-10-03T20:40:01.571482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.

These vulnerabilities exist because the web-based management interface does not validate user input adequately. An attacker could exploit these vulnerabilities by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit these vulnerabilities, an attacker would need Administrator-level privileges.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.



This advisory is part of the October 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: October 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication ["https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300"].</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-fmc-sql-inj-loyafcfq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-44495</id>
    <title>cnvd-2024-44495</title>
    <updated>2026-10-03T20:40:01.571522+00:00</updated>
    <content>cnvd-2024-44495</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-44495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-197231</id>
    <title>EUVD-2026-197231</title>
    <updated>2026-10-03T20:40:01.571537+00:00</updated>
    <content>EUVD-2026-197231</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-197231"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-20472</id>
    <title>fkie_cve-2024-20472</title>
    <updated>2026-10-03T20:40:01.571549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.

This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-20472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-253g-rphr-6h5j</id>
    <title>GHSA-253g-rphr-6h5j</title>
    <updated>2026-10-03T20:40:01.571574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.</p>
<p>This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-253g-rphr-6h5j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-20472</id>
    <title>gsd-2024-20472</title>
    <updated>2026-10-03T20:40:01.571593+00:00</updated>
    <content>gsd-2024-20472</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-20472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3267</id>
    <title>WID-SEC-W-2024-3267 — Cisco Secure Firewall Management Center: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:40:01.571605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Cisco Secure Firewall Management Center ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, vertrauliche Informationen preiszugeben, beliebigen Code auszuführen, Daten zu manipulieren und erhöhte Rechte zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3267"/>
  </entry>
</feed>
