<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T19:35:22.191185+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-231097</id>
    <title>EUVD-2026-231097</title>
    <updated>2026-10-05T19:35:22.265505+00:00</updated>
    <content>EUVD-2026-231097</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-231097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43355</id>
    <title>fkie_cve-2021-43355</title>
    <updated>2026-10-05T19:35:22.265543+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript or intentionally bypass the client-side checks. An attacker with knowledge of the service user could circumvent the client-side control and login with service privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-43355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gc9x-xj3h-72v9</id>
    <title>GHSA-gc9x-xj3h-72v9</title>
    <updated>2026-10-05T19:35:22.265580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript or intentionally bypass the client-side checks. An attacker with knowledge of the service user could circumvent the client-side control and login with service privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gc9x-xj3h-72v9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-43355</id>
    <title>gsd-2021-43355</title>
    <updated>2026-10-05T19:35:22.265600+00:00</updated>
    <content>gsd-2021-43355</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-43355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsma-21-355-01</id>
    <title>ICSMA-21-355-01 — Fresenius Kabi Agilia Connect Infusion System (Update A)</title>
    <updated>2026-10-05T19:35:22.265614+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Requests may be used to interrupt the normal operation of the device. When exploited, Agilia Link+ must be rebooted via a hard reset triggered by pressing a button on the rack system.CVE-2021-23236 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The SSL/TLS configuration of Agilia Link+ has serious deficiencies that may allow an attacker to compromise SSL/TLS sessions in different ways. An attacker may be able to eavesdrop on transferred data, manipulate data allegedly secured by SSL/TLS, and impersonate an entity to gain access to sensitive information.CVE-2021-31562 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). The Agilia Link+ management interface does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service does not perform an automated redirect from the unencrypted service on Port TCP/80 to the encrypted service.CVE-2021-41835 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). The web application on Agilia Link+ implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attr…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsma-21-355-01"/>
  </entry>
</feed>
