<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:06:05.265251+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339984</id>
    <title>EUVD-2026-339984</title>
    <updated>2026-10-03T07:06:05.353788+00:00</updated>
    <content>EUVD-2026-339984</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339984"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15037</id>
    <title>fkie_cve-2026-15037</title>
    <updated>2026-10-03T07:06:05.353826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-15037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7xx4-xq65-r6v3</id>
    <title>GHSA-7xx4-xq65-r6v3</title>
    <updated>2026-10-03T07:06:05.353859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7xx4-xq65-r6v3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-15037</id>
    <title>msrc_CVE-2026-15037 — XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization</title>
    <updated>2026-10-03T07:06:05.353878+00:00</updated>
    <content>msrc_CVE-2026-15037</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-15037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15037</id>
    <title>UBUNTU-CVE-2026-15037</title>
    <updated>2026-10-03T07:06:05.353895+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: qt4-x11, Ubuntu:16.04:LTS: qt4-x11, Ubuntu:Pro:16.04:LTS: qtbase-opensource-src, Ubuntu:Pro:18.04:LTS: qtbase-opensource-src, Ubuntu:18.04:LTS: qt4-x11, Ubuntu:Pro:20.04:LTS: qtbase-opensource-src, Ubuntu:22.04:LTS: qt6-base, Ubuntu:Pro:22.04:LTS: qtbase-opensource-src, Ubuntu:24.04:LTS: qt6-base, Ubuntu:Pro:24.04:LTS: qtbase-opensource-src and 2 more</p>
<p>Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2500</id>
    <title>WID-SEC-W-2026-2500 — QT: Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-03T07:06:05.353933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in QT ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2500"/>
  </entry>
</feed>
