<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:06:46.410464+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-10719</id>
    <title>bdu:2024-10719</title>
    <updated>2026-10-02T19:06:46.416367+00:00</updated>
    <content>bdu:2024-10719</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-10719"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0967</id>
    <title>certfr-2024-avi-0967 — De multiples vulnérabilités ont été découvertes dans les produits Ivanti. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-02T19:06:46.416400+00:00</updated>
    <content>certfr-2024-avi-0967</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0967"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-205246</id>
    <title>EUVD-2026-205246</title>
    <updated>2026-10-02T19:06:46.416435+00:00</updated>
    <content>EUVD-2026-205246</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-205246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38656</id>
    <title>fkie_cve-2024-38656</title>
    <updated>2026-10-02T19:06:46.416447+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-38656"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gvvw-6jh9-63h5</id>
    <title>GHSA-gvvw-6jh9-63h5</title>
    <updated>2026-10-02T19:06:46.416474+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gvvw-6jh9-63h5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/va-24-317-01</id>
    <title>VA-24-317-01 — Ivanti Connect Secure and Ivanti Policy Secure Multiple Vulnerabilities</title>
    <updated>2026-10-02T19:06:46.416490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ivanti Connect Secure before versions 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allow a remote, authenticated attacker with administrative privileges to inject operating system commands using the 'dig' web interface. Ivanti Connect Secure before versions 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allow a remote, authenticated attacker with administrative privileges to inject operating system commands using the 'ping6' web interface. Ivanti Connect Secure before versions 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allow a remote, authenticated attacker with administrative privileges to inject operating system commands using the 'traceroute6' web interface. Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allow allow a remote, authenticated attacker with administrative privileges to write arbitrary files or execute operating system commands with the operating system privileges of the 'nr' user using the diagnostic web interface for the Port Probe ('nmap') feature. Ivanti Connect Secure before version 22.6R2 and Ivanti Policy Secure before version 22.7R1 allow a local, authenticated attacker with 'nr' operating system privileges to gain 'root' privileges by overwriting the 'kwatchdog' configuration file. Ivanti Connect Secure before versions 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allow a remote, authenticated attacker…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/va-24-317-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3433</id>
    <title>WID-SEC-W-2024-3433 — Ivanti Connect Secure: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:06:46.416526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Ivanti Connect Secure, Ivanti Policy Secure und Ivanti Secure Access Client ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, einen Denial-of-Service Zustand zu erzeugen und Daten zu modifizieren</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3433"/>
  </entry>
</feed>
