<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:43:22.792276+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06879</id>
    <title>bdu:2025-06879</title>
    <updated>2026-10-02T18:43:22.875301+00:00</updated>
    <content>bdu:2025-06879</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261632</id>
    <title>EUVD-2026-261632</title>
    <updated>2026-10-02T18:43:22.875340+00:00</updated>
    <content>EUVD-2026-261632</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261632"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-25264</id>
    <title>fkie_cve-2025-25264</title>
    <updated>2026-10-02T18:43:22.875354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-25264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rqg6-587c-h9v3</id>
    <title>GHSA-rqg6-587c-h9v3</title>
    <updated>2026-10-02T18:43:22.875383+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rqg6-587c-h9v3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-018</id>
    <title>VDE-2025-018 — WAGO: Vulnerabilities in WAGO Device Manager</title>
    <updated>2026-10-02T18:43:22.875399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vulnerabilities have been discovered in the WAGO Device Manager that allow any origin to access the server and set header values, as well as an endpoint that permits read access to the file system. The WAGO Device Manager is a software for configuring and parameterizing single WAGO products, which is included in the firmware. These vulnerabilities could be exploited by attackers to send requests and read server responses through crafted web applications or to access the file system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-018"/>
  </entry>
</feed>
