<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T09:21:53.993901+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-14132</id>
    <title>EUVD-2026-14132</title>
    <updated>2026-10-09T09:21:54.054173+00:00</updated>
    <content>EUVD-2026-14132</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-14132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24374</id>
    <title>fkie_cve-2022-24374</title>
    <updated>2026-10-09T09:21:54.054219+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-23916.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24374"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g667-p784-m7j2</id>
    <title>GHSA-g667-p784-m7j2</title>
    <updated>2026-10-09T09:21:54.054253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-23916.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g667-p784-m7j2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24374</id>
    <title>gsd-2022-24374</title>
    <updated>2026-10-09T09:21:54.054271+00:00</updated>
    <content>gsd-2022-24374</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24374"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2022-000014</id>
    <title>jvndb-2022-000014</title>
    <updated>2026-10-09T09:21:54.054282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>a-blog cms provided by appleple inc. contains multiple vulnerabilities listed below. 
* Cross-site scripting (CWE-79) - CVE-2022-24374
* Cross-site scripting (CWE-79) - CVE-2022-23916
* Template injection (CWE-1336) - CVE-2022-23810
* Authentication bypass (CWE-291) - CVE-2022-21142

CVE-2022-24374
iwama yuu of Secure Sky Technology Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2022-23916
Masashi Yamane of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2022-23810, CVE-2022-21142
hibiki moriyama of STNet, Incorporated reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2022-000014"/>
  </entry>
</feed>
