<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T07:07:11.012626+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-252060</id>
    <title>EUVD-2026-252060</title>
    <updated>2026-10-10T07:07:11.302052+00:00</updated>
    <content>EUVD-2026-252060</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-252060"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55037</id>
    <title>fkie_cve-2025-55037</title>
    <updated>2026-10-10T07:07:11.302093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote unauthenticated attacker if the settings are configured to construct messages from external sources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-55037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hfrj-3w3g-jv32</id>
    <title>GHSA-hfrj-3w3g-jv32 — TkEasyGUI Vulnerable to OS Command Injection</title>
    <updated>2026-10-10T07:07:11.302130+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: TkEasyGUI</p>
<p>Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote unauthenticated attacker if the settings are configured to construct messages from external sources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hfrj-3w3g-jv32"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2025-000075</id>
    <title>jvndb-2025-000075</title>
    <updated>2026-10-10T07:07:11.302155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TkEasyGUI provided by kujirahand contains multiple vulnerabilities listed below.&lt;ul&gt;&lt;li&gt;OS command injection (CWE-78) - CVE-2025-55037&lt;/li&gt;&lt;li&gt;Uncontrolled search path element (CWE-427) - CVE-2025-55671&lt;/li&gt;&lt;/ul&gt;
Satoki Tsuji of Ikotas Labs, Inc. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2025-000075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-552</id>
    <title>PYSEC-2026-552 — TkEasyGUI Vulnerable to OS Command Injection</title>
    <updated>2026-10-10T07:07:11.302176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tkeasygui</p>
<p>Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote unauthenticated attacker if the settings are configured to construct messages from external sources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-552"/>
  </entry>
</feed>
