<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:52:24.567866+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264435</id>
    <title>EUVD-2026-264435</title>
    <updated>2026-10-02T20:52:24.649921+00:00</updated>
    <content>EUVD-2026-264435</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14922</id>
    <title>fkie_cve-2025-14922</title>
    <updated>2026-10-02T20:52:24.649956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.</p>
<p>The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27424.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-14922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7g8m-37xj-mmcx</id>
    <title>GHSA-7g8m-37xj-mmcx</title>
    <updated>2026-10-02T20:52:24.649993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.</p>
<p>The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27424.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7g8m-37xj-mmcx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:3713</id>
    <title>RHSA-2026:3713 — Red Hat Security Advisory: RHOAI 3.3 - Red Hat OpenShift AI</title>
    <updated>2026-10-02T20:52:24.650014+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/containerd/containerd: containerd local privilege escalation vllm: Server Side request forgery (SSRF) in MediaConnector keras: Path Traversal Vulnerability in keras node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications php: PHP: Denial of Service via invalid character sequence in PDO PostgreSQL prepared statement transformers: code execution when processing a malicious Perceiver model file transformers: code execution when processing a malicious Transformer-XL model file diffusers: Hugging Face Diffusers: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when processing a malicious megatron_gpt2 model file accelerate: Hugging Face Accelerate: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when converting a malicious SEW model checkpoint transformers: code execution when converting a malicious SEW-D model checkpoint transformers: code execution when converting a malicious HuBERT model checkpoint transformers: code execution when processing a malicious X-CLIP model file transformers: code execution when processing a malicious GLM4 model file qs: qs: Denial of Service via improper input validation in array parsing vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects v…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:3713"/>
  </entry>
</feed>
