<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:31:08.324444+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-00858</id>
    <title>cnvd-2016-00858</title>
    <updated>2026-10-03T23:31:08.348827+00:00</updated>
    <content>cnvd-2016-00858</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-00858"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-95091</id>
    <title>EUVD-2026-95091</title>
    <updated>2026-10-03T23:31:08.348883+00:00</updated>
    <content>EUVD-2026-95091</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-95091"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2015-7537</id>
    <title>fkie_cve-2015-7537</title>
    <updated>2026-10-03T23:31:08.348906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2015-7537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3vhr-f5xr-8vpx</id>
    <title>GHSA-3vhr-f5xr-8vpx — Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack</title>
    <updated>2026-10-03T23:31:08.348951+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.main:jenkins-core</p>
<p>Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3vhr-f5xr-8vpx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2015-7537</id>
    <title>gsd-2015-7537</title>
    <updated>2026-10-03T23:31:08.348992+00:00</updated>
    <content>gsd-2015-7537</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2015-7537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:0070</id>
    <title>RHSA-2016:0070 — Red Hat Security Advisory: Red Hat OpenShift Enterprise 3.1.1 bug fix and enhancement update</title>
    <updated>2026-10-03T23:31:08.349011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>commons-fileupload: Arbitrary file upload via deserialization stapler-adjunct-zeroclipboard: multiple cross-site scripting (XSS) flaws jenkins: denial of service (SECURITY-87) jenkins: username discovery (SECURITY-110) jenkins: job configuration issues (SECURITY-127, SECURITY-128) jenkins: directory traversal flaw (SECURITY-131) jenkins: remote code execution flaw (SECURITY-150) jenkins: plug-in code can be downloaded by anyone with read access (SECURITY-155) jenkins: password exposure in DOM (SECURITY-138) jenkins: cross-site scripting flaw in Jenkins core (SECURITY-143) jenkins: Combination filter Groovy script unsecured (SECURITY-125) jenkins: directory traversal from artifacts via symlink (SECURITY-162) jenkins: update center metadata retrieval DoS attack (SECURITY-163) jenkins: HudsonPrivateSecurityRealm allows creation of reserved names (SECURITY-166) jenkins: Reflective XSS vulnerability (SECURITY-171, SECURITY-177) jenkins: Reflective XSS vulnerability (SECURITY-171, SECURITY-177) jenkins: forced API token change (SECURITY-180) jenkins: Project name disclosure via fingerprints (SECURITY-153) jenkins: Public value used for CSRF protection salt (SECURITY-169) jenkins: XXE injection into job configurations via CLI (SECURITY-173) jenkins: Secret key not verified when connecting a slave (SECURITY-184) jenkins: Information disclosure via sidepanel (SECURITY-192) jenkins: Local file inclusion vulnerability (SECURITY-195) jenkins: API tokens of other users available to admin…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:0070"/>
  </entry>
</feed>
