<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T12:34:17.979478+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-52459</id>
    <title>CVE-2025-52459 — Advantech iView Argument Injection</title>
    <updated>2026-10-09T12:34:17.981306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Advantech iView</p>
<p>A vulnerability exists in Advantech iView that allows for argument 
injection in NetworkServlet.backupDatabase(). This issue requires an 
authenticated attacker with at least user-level privileges. Certain 
parameters can be used directly in a command without proper 
sanitization, allowing arbitrary arguments to be injected. This can 
result in information disclosure, including sensitive database 
credentials.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-52459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-191-08</id>
    <title>ICSA-25-191-08 — Advantech iView</title>
    <updated>2026-10-09T12:34:17.981363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities. A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities. A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities. A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure or a denial-of-service condition. A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privilege…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-191-08"/>
  </entry>
</feed>
