<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T23:32:20.129927+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2018-01195</id>
    <title>bdu:2018-01195</title>
    <updated>2026-10-04T23:32:20.210339+00:00</updated>
    <content>bdu:2018-01195</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2018-01195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-21174</id>
    <title>cnvd-2018-21174</title>
    <updated>2026-10-04T23:32:20.210383+00:00</updated>
    <content>cnvd-2018-21174</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-21174"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-177606</id>
    <title>EUVD-2026-177606</title>
    <updated>2026-10-04T23:32:20.210403+00:00</updated>
    <content>EUVD-2026-177606</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-177606"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-17889</id>
    <title>fkie_cve-2018-17889</title>
    <updated>2026-10-04T23:32:20.210422+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-17889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8j9h-qgqg-vvwq</id>
    <title>GHSA-8j9h-qgqg-vvwq</title>
    <updated>2026-10-04T23:32:20.210465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8j9h-qgqg-vvwq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-17889</id>
    <title>gsd-2018-17889</title>
    <updated>2026-10-04T23:32:20.210493+00:00</updated>
    <content>gsd-2018-17889</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-17889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-18-277-01</id>
    <title>ICSA-18-277-01 — WECON PI Studio (Update A)</title>
    <updated>2026-10-04T23:32:20.210511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When parsing specific files the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code under the context of an administrator.CVE-2018-14818 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). When parsing specific files the process does not properly validate user-supplied data, which can result in multiple write instances past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of an administrator.CVE-2018-14810 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). When parsing project files the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.CVE-2018-17889 has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). When parsing specific files the process does not properly validate user-supplied data, which can result in a read past the end of an allocated object. CVE-2018-14814 has been assigned to this vulnerability. A CVSS v3 base score of 3.3 has been calculated; the CVSS vector string is (AV:L/…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-18-277-01"/>
  </entry>
</feed>
