<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:47:57.676789+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-273999</id>
    <title>EUVD-2026-273999</title>
    <updated>2026-10-03T23:47:57.747869+00:00</updated>
    <content>EUVD-2026-273999</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-273999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24689</id>
    <title>fkie_cve-2026-24689</title>
    <updated>2026-10-03T23:47:57.747926+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An OS command injection</p>
<p>vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an 
authenticated attacker to achieve remote code execution on the system by
 injecting malicious input into the devices field of the firmware update
 apply action.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-24689"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p8c6-r53p-q435</id>
    <title>GHSA-p8c6-r53p-q435</title>
    <updated>2026-10-03T23:47:57.747976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An OS command injection</p>
<p>vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an 
authenticated attacker to achieve remote code execution on the system by
 injecting malicious input into the devices field of the firmware update
 apply action.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p8c6-r53p-q435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-057-10</id>
    <title>ICSA-26-057-10 — Copeland XWEB and XWEB Pro</title>
    <updated>2026-10-03T23:47:57.747997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass. An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system. An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body. An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body sent to the contacts import route. An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the restore route. An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route. An OS Command injection vulnerability exists in XWEB…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-057-10"/>
  </entry>
</feed>
