<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T22:54:27.928936+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-43726</id>
    <title>EUVD-2026-43726</title>
    <updated>2026-10-09T22:54:28.013892+00:00</updated>
    <content>EUVD-2026-43726</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-43726"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-17483</id>
    <title>fkie_cve-2020-17483</title>
    <updated>2026-10-09T22:54:28.013930+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it responds with a JSON body that has all the details about the devices which have been deployed.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-17483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jj8x-8hrh-x979</id>
    <title>GHSA-jj8x-8hrh-x979</title>
    <updated>2026-10-09T22:54:28.013962+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it responds with a JSON body that has all the details about the devices which have been deployed.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jj8x-8hrh-x979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-17483</id>
    <title>gsd-2020-17483</title>
    <updated>2026-10-09T22:54:28.013980+00:00</updated>
    <content>gsd-2020-17483</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-17483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-287-02</id>
    <title>ICSA-21-287-02 — Uffizio GPS Tracker</title>
    <updated>2026-10-09T22:54:28.013992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Visiting through the browser or doing curl on the vulnerable host at Port 9000 responds with JSON body, revealing information about deployed GPS devices.CVE-2020-17483 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The web server can be compromised by uploading and executing a web/reverse shell. An attacker could then run commands, browse system files, and browse local resources.CVE-2020-17485 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker can construct a URL within the application that causes a redirection to an arbitrary external domain.CVE-2020-17484 has been assigned to this vulnerability. A CVSS v3 base score of 4.7 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N). An attacker may be able to inject client-side JavaScript code on multiple instances within the application.CVE-2021-32927 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L). This application-wide vulnerability may allow an attacker to perform unintended actions on behalf of a user.CVE-2021-32929 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-287-02"/>
  </entry>
</feed>
