<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:09:54.303839+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-175557</id>
    <title>EUVD-2026-175557</title>
    <updated>2026-10-03T19:09:54.376130+00:00</updated>
    <content>EUVD-2026-175557</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-175557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2012-5055</id>
    <title>fkie_cve-2012-5055</title>
    <updated>2026-10-03T19:09:54.376167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2012-5055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3533-rvpc-6x56</id>
    <title>GHSA-3533-rvpc-6x56 — Exposure of Sensitive Information to an Unauthorized Actor in Spring Security</title>
    <updated>2026-10-03T19:09:54.376200+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework.security:spring-security-core</p>
<p>DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3533-rvpc-6x56"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2012-5055</id>
    <title>gsd-2012-5055</title>
    <updated>2026-10-03T19:09:54.376227+00:00</updated>
    <content>gsd-2012-5055</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2012-5055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2013:0649</id>
    <title>RHSA-2013:0649 — Red Hat Security Advisory: Fuse ESB Enterprise 7.1.0 update</title>
    <updated>2026-10-03T19:09:54.376240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security: Ability to determine if username is valid via DaoAuthenticationProvider apache-cxf: Bypass of security constraints on WS endpoints when using WSS4JInInterceptor apache-cxf: UsernameTokenPolicyValidator and UsernameTokenInterceptor allow empty passwords to authenticate</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2013:0649"/>
  </entry>
</feed>
