<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:36:19.142728+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0948</id>
    <title>certfr-2024-avi-0948 — De multiples vulnérabilités ont été découvertes dans les produits Symfony. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-03T22:36:19.195354+00:00</updated>
    <content>certfr-2024-avi-0948</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0948"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-203677</id>
    <title>EUVD-2026-203677</title>
    <updated>2026-10-03T22:36:19.195394+00:00</updated>
    <content>EUVD-2026-203677</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-203677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-51736</id>
    <title>fkie_cve-2024-51736</title>
    <updated>2026-10-03T22:36:19.195408+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has been addressed in release versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-51736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qq5c-677p-737q</id>
    <title>GHSA-qq5c-677p-737q — Symfony vulnerable to command execution hijack on Windows with Process class</title>
    <updated>2026-10-03T22:36:19.195439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: symfony/process, Packagist: symfony/symfony</p>
<p>### Description</p>
<p>On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking.</p>
<p>### Resolution</p>
<p>The `Process` class now uses the absolute path to `cmd.exe`.</p>
<p>The patch for this issue is available [here](https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9) for branch 5.4.</p>
<p>### Credits</p>
<p>We would like to thank Jordi Boggiano for reporting the issue and Nicolas Grekas for providing the fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qq5c-677p-737q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0447</id>
    <title>WID-SEC-W-2026-0447 — Moodle: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:36:19.195472+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Moodle ausnutzen, um beliebigen Programmcode auszuführen und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0447"/>
  </entry>
</feed>
