<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:01:54.254695+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08006</id>
    <title>bdu:2025-08006</title>
    <updated>2026-10-03T12:01:54.327811+00:00</updated>
    <content>bdu:2025-08006</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-22705</id>
    <title>cnvd-2025-22705</title>
    <updated>2026-10-03T12:01:54.327847+00:00</updated>
    <content>cnvd-2025-22705</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-22705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248973</id>
    <title>EUVD-2026-248973</title>
    <updated>2026-10-03T12:01:54.327862+00:00</updated>
    <content>EUVD-2026-248973</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248973"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52997</id>
    <title>fkie_cve-2025-52997</title>
    <updated>2026-10-03T12:01:54.327875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers could mount a brute-force attack to retrieve the passwords of all accounts in a given instance. This issue has been patched in version 2.34.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-52997"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cm2r-rg7r-p7gg</id>
    <title>GHSA-cm2r-rg7r-p7gg — File Browser vulnerable to insecure password handling</title>
    <updated>2026-10-03T12:01:54.327905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser</p>
<p>## Summary ##</p>
<p>All user accounts authenticate towards a *File Browser* instance with a password. A missing password policy and brute-force protection makes it impossible for administrators to properly secure the authentication process.</p>
<p>## Impact ##</p>
<p>Attackers can mount a brute-force attack against the passwords of all accounts of an instance. Since the application is lacking the ability to prevent users from choosing a weak password, the attack is likely to succeed.</p>
<p>## Vulnerability Description ##</p>
<p>The application implement a classical authentication scheme using a username and password combination. While employed by many systems, this scheme is quite error-prone and a common cause for vulnerabilities. File Browser's implementation has multiple weak points:</p>
<p>1. Since the application is missing the capability for administrators to define a password policy, users are at liberty to set trivial and well-known passwords such as `secret` or even ones with only single digit like `1`.
2. New instances are set up with a default password of `admin` for the initial administrative account. This password is well known and easily guessable. While the documentation advises to change this password, the application does not technically enforce it.
3. The application does not implement any brute-force protection for the authentication endpoint. Attackers can make as many guesses for a password as the network bandwidth allows.</p>
<p>The combination of these problems makes it likely, that an attac…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cm2r-rg7r-p7gg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</id>
    <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
    <updated>2026-10-03T12:01:54.327968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1"/>
  </entry>
</feed>
