<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T05:18:41.512694+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-22645</id>
    <title>cnvd-2022-22645</title>
    <updated>2026-10-09T05:18:41.518466+00:00</updated>
    <content>cnvd-2022-22645</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-22645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-21900</id>
    <title>EUVD-2026-21900</title>
    <updated>2026-10-09T05:18:41.518513+00:00</updated>
    <content>EUVD-2026-21900</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-21900"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-20837</id>
    <title>fkie_cve-2021-20837</title>
    <updated>2026-10-09T05:18:41.518534+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-20837"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fq4q-8q83-6gj7</id>
    <title>GHSA-fq4q-8q83-6gj7</title>
    <updated>2026-10-09T05:18:41.518594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fq4q-8q83-6gj7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-20837</id>
    <title>gsd-2021-20837</title>
    <updated>2026-10-09T05:18:41.518615+00:00</updated>
    <content>gsd-2021-20837</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-20837"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2021-000093</id>
    <title>jvndb-2021-000093</title>
    <updated>2026-10-09T05:18:41.518627+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Movable Type XMLRPC API provided by Six Apart Ltd. contains an OS command injection vulnerability (CWE-78).
Sending a specially crafted message by POST method to Movavle Type XMLRPC API may allow arbitrary OS command execution.

[Updated on 2021 November 10]
As of 2021 November 10, a Proof-of-Concept (PoC) code exploitning this vulnerability has already been made public and attacks exploting this vulnerability has been observed in the wild.

&amp;#201;tienne Gervais, Charl-Alexandre Le Brun and Chatwork Co., Ltd. reported this vulnerability to Six Apart Ltd. and coordinated.
Six Apart Ltd. reported this vulnerability to JPCERT/CC to notify users of the solution through JVN.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2021-000093"/>
  </entry>
</feed>
