<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T13:33:31.243582+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-240075</id>
    <title>EUVD-2026-240075</title>
    <updated>2026-10-10T13:33:31.246530+00:00</updated>
    <content>EUVD-2026-240075</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-240075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-47889</id>
    <title>fkie_cve-2025-47889</title>
    <updated>2026-10-10T13:33:31.246571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-47889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p89h-p4ph-4vj6</id>
    <title>GHSA-p89h-p4ph-4vj6 — Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials</title>
    <updated>2026-10-10T13:33:31.246603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.plugins:wso2id-oauth</p>
<p>In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p89h-p4ph-4vj6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1052</id>
    <title>WID-SEC-W-2025-1052 — Jenkins Plugins: Mehrere Schwachstellen</title>
    <updated>2026-10-10T13:33:31.246628+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Jenkins-Plugins ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und Cross-Site-Scripting-Angriffe durchzuführen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1052"/>
  </entry>
</feed>
