<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T20:42:28.470039+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06864</id>
    <title>bdu:2025-06864</title>
    <updated>2026-10-09T20:42:28.473530+00:00</updated>
    <content>bdu:2025-06864</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06864"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0519</id>
    <title>certfr-2025-avi-0519 — De multiples vulnérabilités ont été découvertes dans Moodle. Certaines d'entre elles permettent à un attaquant de provo…</title>
    <updated>2026-10-09T20:42:28.473562+00:00</updated>
    <content>certfr-2025-avi-0519</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241247</id>
    <title>EUVD-2026-241247</title>
    <updated>2026-10-09T20:42:28.473580+00:00</updated>
    <content>EUVD-2026-241247</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46337</id>
    <title>fkie_cve-2025-46337</title>
    <updated>2026-10-09T20:42:28.473592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data. This issue has been patched in version 5.22.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-46337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8x27-jwjr-8545</id>
    <title>GHSA-8x27-jwjr-8545 — SQL injection in ADOdb PostgreSQL driver pg_insert_id() method</title>
    <updated>2026-10-09T20:42:28.473619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: adodb/adodb-php</p>
<p>Improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data.</p>
<p>Note that the indicated Severity corresponds to a worst-case usage scenario.</p>
<p>### Impact
PostgreSQL drivers (postgres64, postgres7, postgres8, postgres9).</p>
<p>### Patches
Vulnerability is fixed in ADOdb 5.22.9 (11107d6d6e5160b62e05dff8a3a2678cf0e3a426).</p>
<p>### Workarounds
Only pass controlled data to pg_insert_id() method's $fieldname parameter, or escape it with pg_escape_identifier() first.</p>
<p>### References
- Issue https://github.com/ADOdb/ADOdb/issues/1070
- [Blog post](https://xaliom.blogspot.com/2025/05/from-sast-to-cve-2025-46337.html) by Marco Nappi</p>
<p>### Credits
Thanks to Marco Nappi (@mrcnpp) for reporting this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8x27-jwjr-8545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46337</id>
    <title>UBUNTU-CVE-2025-46337</title>
    <updated>2026-10-09T20:42:28.473649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: libphp-adodb, Ubuntu:Pro:20.04:LTS: libphp-adodb, Ubuntu:Pro:22.04:LTS: libphp-adodb, Ubuntu:Pro:24.04:LTS: libphp-adodb, Ubuntu:25.10: libphp-adodb, Ubuntu:26.04:LTS: libphp-adodb</p>
<p>ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data. This issue has been patched in version 5.22.9.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-46337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1353</id>
    <title>WID-SEC-W-2025-1353 — Moodle: Mehrere Schwachstellen</title>
    <updated>2026-10-09T20:42:28.473675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Moodle ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Informationen offenzulegen, Sicherheitsmechanismen zu umgehen und um nicht näher spezifizierte Auswirkungen zu erzielen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1353"/>
  </entry>
</feed>
