<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T17:15:57.364192+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217323</id>
    <title>EUVD-2026-217323</title>
    <updated>2026-10-04T17:15:57.384897+00:00</updated>
    <content>EUVD-2026-217323</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27163</id>
    <title>fkie_cve-2024-27163</title>
    <updated>2026-10-04T17:15:57.384937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. An attacker stealing the cookie of an admin or abusing a XSS vulnerability can recover this password in clear-text and compromise the printer. This vulnerability can be executed in combination with other vulnerabilities and  difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point.
 https://www.toshibatec.com/contacts/products/ 
As for the affected products/models/versions, see the reference URL.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-27163"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wjcq-p2hh-4gr7</id>
    <title>GHSA-wjcq-p2hh-4gr7</title>
    <updated>2026-10-04T17:15:57.384975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. An attacker stealing the cookie of an admin or abusing a XSS vulnerability can recover this password in clear-text and compromise the printer. This vulnerability can be executed in combination with other vulnerabilities and  difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point.
 https://www.toshibatec.com/contacts/products/ 
As for the affected products/models/versions, see the reference URL.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wjcq-p2hh-4gr7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-27163</id>
    <title>gsd-2024-27163</title>
    <updated>2026-10-04T17:15:57.384997+00:00</updated>
    <content>gsd-2024-27163</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-27163"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2024-003539</id>
    <title>jvndb-2024-003539</title>
    <updated>2026-10-04T17:15:57.385009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MFPs (multifunction printers) provided by Toshiba Tec Corporation and Oki Electric Industry Co., Ltd. contain multiple vulnerabilities listed below.
&lt;ul&gt;
	&lt;li&gt;&lt;b&gt;Improper Restriction of Recursive Entity References in DTDs (&amp;#39;XML Entity Expansion&amp;#39;) (&lt;a href="https://cwe.mitre.org/data/definitions/776"&gt;CWE-776&lt;/a&gt;) &lt;/b&gt;- CVE-2024-27141, CVE-2024-27142&lt;/li&gt;
	&lt;li&gt;&lt;b&gt;Execution with Unnecessary Privileges (&lt;a href="https://cwe.mitre.org/data/definitions/250"&gt;CWE-250&lt;/a&gt;) &lt;/b&gt;- CVE-2024-27143, CVE-2024-27146, CVE-2024-27147, CVE-2024-3498&lt;/li&gt;
	&lt;li&gt;&lt;b&gt;Incorrect Default Permissions (&lt;a href="https://cwe.mitre.org/data/definitions/276"&gt;CWE-276&lt;/a&gt;) &lt;/b&gt;- CVE-2024-27148, CVE-2024-27149, CVE-2024-27150, CVE-2024-27151, CVE-2024-27152, CVE-2024-27153, CVE-2024-27155, CVE-2024-27167, CVE-2024-27171&lt;/li&gt;
	&lt;li&gt;&lt;b&gt;Path Traversal (&lt;a href="https://cwe.mitre.org/data/definitions/22"&gt;CWE-22&lt;/a&gt;) &lt;/b&gt;- CVE-2024-27144, CVE-2024-27145, CVE-2024-27173, CVE-2024-27174, CVE-2024-27176, CVE-2024-27177, CVE-2024-27178&lt;/li&gt;
	&lt;li&gt;&lt;b&gt;Insertion of Sensitive Information into Log File (&lt;a href="https://cwe.mitre.org/data/definitions/532"&gt;CWE-532&lt;/a&gt;) &lt;/b&gt;- CVE-2024-27154, CVE-2024-27156, CVE-2024-27157&lt;/li&gt;
	&lt;li&gt;&lt;b&gt;Plaintext Storage of a Password (&lt;a href="https://cwe.mitre.org/data/definitions/256"&gt;CWE-256&lt;/a&gt;) &lt;/b&gt;- CVE-2024-27166&lt;/li&gt;
	&lt;li&gt;&lt;b&gt;Debug Messages Revealing Unnecessary Information (&lt;a href="https://cwe.mitre.org/data/definitions/1295"&gt;CWE-1295&lt;/a&gt;) &lt;/b&gt;- CVE-2024-27179&lt;/li&gt;
	&lt;li…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2024-003539"/>
  </entry>
</feed>
