<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T11:05:33.470223+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-07695</id>
    <title>bdu:2024-07695</title>
    <updated>2026-10-04T11:05:33.521310+00:00</updated>
    <content>bdu:2024-07695</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-07695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-39680</id>
    <title>cnvd-2024-39680</title>
    <updated>2026-10-04T11:05:33.521345+00:00</updated>
    <content>cnvd-2024-39680</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-39680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-189537</id>
    <title>EUVD-2026-189537</title>
    <updated>2026-10-04T11:05:33.521359+00:00</updated>
    <content>EUVD-2026-189537</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-189537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-39275</id>
    <title>fkie_cve-2024-39275</title>
    <updated>2026-10-04T11:05:33.521371+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a 
session is closed. Forging requests with a legitimate cookie, even if 
the session was terminated, allows an unauthorized attacker to act with 
the same level of privileges of the legitimate user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-39275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r29x-667c-gv4v</id>
    <title>GHSA-r29x-667c-gv4v</title>
    <updated>2026-10-04T11:05:33.521400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a 
session is closed. Forging requests with a legitimate cookie, even if 
the session was terminated, allows an unauthorized attacker to act with 
the same level of privileges of the legitimate user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r29x-667c-gv4v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-270-02</id>
    <title>ICSA-24-270-02 — Advantech ADAM 5630</title>
    <updated>2026-10-04T11:05:33.521415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cookies of authenticated users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user. Cross-site request forgery (CSRF) is a web security vulnerability that allows an attacker to induce users to perform actions that they do not intend to perform. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other. User credentials are shared in plain text, between the device and the user source device, during the login process. The device has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without discrimination of origin or level of privileges of the user sending the commands.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-270-02"/>
  </entry>
</feed>
