<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:45:44.177617+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-2901</id>
    <title>fkie_cve-2025-2901</title>
    <updated>2026-10-03T05:45:44.188520+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rejected reason: This vulnerability is redundant to CVE-2025-23366 and CVE-2024-10234.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-2901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f7jh-m6wp-jm7f</id>
    <title>GHSA-f7jh-m6wp-jm7f — HAL Cross Site Scripting (XSS) vulnerability of user input when storing it in a data store</title>
    <updated>2026-10-03T05:45:44.188569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jboss.hal:hal-console</p>
<p>A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities.</p>
<p>### Impact
Cross-site scripting (XSS) vulnerability in the management console.</p>
<p>### Patches
Fixed in [HAL 3.7.11.Final](https://github.com/hal/console/releases/tag/v3.7.11)</p>
<p>### Workarounds
No workaround available</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f7jh-m6wp-jm7f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10452</id>
    <title>RHSA-2025:10452 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.8 Security update</title>
    <updated>2026-10-03T05:45:44.188606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.jboss.eap:wildfly-ejb3: Improper Deserialization in JBoss Marshalling Allows Remote Code Execution org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files base-x: base-x homograph attack allows Unicode lookalike characters to bypass validation. commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10452"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0650</id>
    <title>WID-SEC-W-2025-0650 — Red Hat JBoss Enterprise Application Platform: Schwachstelle ermöglicht Cross-Site Scripting</title>
    <updated>2026-10-03T05:45:44.188633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat JBoss Enterprise Application Platform ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0650"/>
  </entry>
</feed>
