<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T12:48:39.104799+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:2566</id>
    <title>ALSA-2024:2566 — Important: pcp security, bug fix, and enhancement update</title>
    <updated>2026-10-04T12:48:39.160107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: pcp, AlmaLinux:9: pcp-conf, AlmaLinux:9: pcp-devel, AlmaLinux:9: pcp-doc, AlmaLinux:9: pcp-export-pcp2elasticsearch, AlmaLinux:9: pcp-export-pcp2graphite, AlmaLinux:9: pcp-export-pcp2influxdb, AlmaLinux:9: pcp-export-pcp2json, AlmaLinux:9: pcp-export-pcp2spark, AlmaLinux:9: pcp-export-pcp2xml and 94 more</p>
<p>Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.</p>
<p>Security Fix(es):</p>
<p>* pcp: exposure of the redis server backend allows remote command execution via pmproxy (CVE-2024-3019)</p>
<p>For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:2566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02823</id>
    <title>bdu:2024-02823</title>
    <updated>2026-10-04T12:48:39.160321+00:00</updated>
    <content>bdu:2024-02823</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02823"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</id>
    <title>certfr-2024-avi-0579 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T12:48:39.160342+00:00</updated>
    <content>certfr-2024-avi-0579</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261409</id>
    <title>EUVD-2026-261409</title>
    <updated>2026-10-04T12:48:39.160358+00:00</updated>
    <content>EUVD-2026-261409</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261409"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-3019</id>
    <title>fkie_cve-2024-3019</title>
    <updated>2026-10-04T12:48:39.160369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-3019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g58w-wr93-q367</id>
    <title>GHSA-g58w-wr93-q367</title>
    <updated>2026-10-04T12:48:39.160394+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g58w-wr93-q367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-3019</id>
    <title>gsd-2024-3019</title>
    <updated>2026-10-04T12:48:39.160411+00:00</updated>
    <content>gsd-2024-3019</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-3019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1435</id>
    <title>OESA-2024-1435 — pcp security update</title>
    <updated>2026-10-04T12:48:39.160421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: pcp</p>
<p>PCP provides a range of services that may be used to monitor and manage system performance. These services are distributed and scalable to accommodate the most complex system configurations and performance problems.

Security Fix(es):

A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the &amp;apos;Metrics settings&amp;apos; page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.(CVE-2024-3019)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2566</id>
    <title>RHSA-2024:2566 — Red Hat Security Advisory: pcp security, bug fix, and enhancement update</title>
    <updated>2026-10-04T12:48:39.160445+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pcp: exposure of the redis server backend allows remote command execution via pmproxy</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:3321</id>
    <title>RHSA-2024:3321 — Red Hat Security Advisory: pcp security update</title>
    <updated>2026-10-04T12:48:39.160463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pcp: exposure of the redis server backend allows remote command execution via pmproxy</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:3321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3533-1</id>
    <title>SUSE-SU-2024:3533-1 — Security update for pcp</title>
    <updated>2026-10-04T12:48:39.160478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for pcp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3533-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3019</id>
    <title>UBUNTU-CVE-2024-3019</title>
    <updated>2026-10-04T12:48:39.160493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: pcp, Ubuntu:18.04:LTS: pcp, Ubuntu:20.04:LTS: pcp, Ubuntu:22.04:LTS: pcp, Ubuntu:24.04:LTS: pcp, Ubuntu:25.10: pcp, Ubuntu:26.04:LTS: pcp</p>
<p>A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1003</id>
    <title>WID-SEC-W-2024-1003 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-04T12:48:39.160521+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, Cross-Site Scripting (XSS)-Angriffe durchzuführen oder einen Men-in-the-Middle-Angriff auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1003"/>
  </entry>
</feed>
