<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:18:01.821289+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00201</id>
    <title>bdu:2026-00201</title>
    <updated>2026-10-03T21:18:01.920059+00:00</updated>
    <content>bdu:2026-00201</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00201"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275246</id>
    <title>EUVD-2026-275246</title>
    <updated>2026-10-03T21:18:01.920097+00:00</updated>
    <content>EUVD-2026-275246</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40801</id>
    <title>fkie_cve-2025-40801</title>
    <updated>2026-10-03T21:18:01.920113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been identified in COMOS V10.6 (All versions &lt; V10.6.1), COMOS V10.6 (All versions &lt; V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions &lt; V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions &lt; V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions &lt; V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions &lt; V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions &lt; V2506.0001), Simcenter System Architect (All versions &lt; V2506.0001), Tecnomatix Plant Simulation (All versions &lt; V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3p2p-55rm-xcvw</id>
    <title>GHSA-3p2p-55rm-xcvw</title>
    <updated>2026-10-03T21:18:01.920149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions &lt; V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions &lt; V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions &lt; V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions &lt; V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions), Simcenter System Architect (All versions), Tecnomatix Plant Simulation (All versions &lt; V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3p2p-55rm-xcvw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-345-05</id>
    <title>ICSA-25-345-05 — Siemens Advanced Licensing (SALT) Toolkit</title>
    <updated>2026-10-03T21:18:01.920171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-345-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-212953</id>
    <title>SSA-212953 — SSA-212953: Multiple Vulnerabilities in COMOS</title>
    <updated>2026-10-03T21:18:01.920190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password. DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. curl's websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.</p>
<p>A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy. The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-mid…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-212953"/>
  </entry>
</feed>
