<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:03:28.863950+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-14089</id>
    <title>cnvd-2019-14089</title>
    <updated>2026-10-03T18:03:28.929587+00:00</updated>
    <content>cnvd-2019-14089</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-14089"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-324098</id>
    <title>EUVD-2026-324098</title>
    <updated>2026-10-03T18:03:28.929634+00:00</updated>
    <content>EUVD-2026-324098</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-324098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-14850</id>
    <title>fkie_cve-2017-14850</title>
    <updated>2026-10-03T18:03:28.929655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with access to the web interface is able to hijack sessions or navigate victims outside of SiteOmat, to a malicious server owned by him.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-14850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w63m-q7q5-grjw</id>
    <title>GHSA-w63m-q7q5-grjw</title>
    <updated>2026-10-03T18:03:28.929700+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with access to the web interface is able to hijack sessions or navigate victims outside of SiteOmat, to a malicious server owned by him.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w63m-q7q5-grjw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-14850</id>
    <title>gsd-2017-14850</title>
    <updated>2026-10-03T18:03:28.929729+00:00</updated>
    <content>gsd-2017-14850</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-14850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-19-122-01</id>
    <title>ICSA-19-122-01 — Orpak SiteOmat</title>
    <updated>2026-10-03T18:03:28.929748+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The application utilizes hard coded username and password credentials for application login.CVE-2017-14728 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The application web interface does not properly neutralize user-controllable input, which could allow cross-site scripting.CVE-2017-14850 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). The application does not properly sanitize external input, which may allow an attacker to access the product by specially crafted input.CVE-2017-14851 has been assigned to this vulnerability. A CVSS v3 base score of 9.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). The application transmits information in plain text, including credentials, which could allow an attacker with access to transmitted data to obtain credentials and bypass authentication.CVE-2017-14852 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L). The application does not properly restrict syntax from external input, which could allow unauthenticated users to execute specially crafted code on the target system.CVE-2017-14853 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been assigned; the CVSS vect…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-19-122-01"/>
  </entry>
</feed>
