<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T11:33:47.304476+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-240021</id>
    <title>EUVD-2026-240021</title>
    <updated>2026-10-09T11:33:47.370139+00:00</updated>
    <content>EUVD-2026-240021</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-240021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27566</id>
    <title>fkie_cve-2025-27566</title>
    <updated>2026-10-09T11:33:47.370176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-27566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w57q-v7qr-v5m7</id>
    <title>GHSA-w57q-v7qr-v5m7</title>
    <updated>2026-10-09T11:33:47.370209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w57q-v7qr-v5m7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2025-005050</id>
    <title>jvndb-2025-005050</title>
    <updated>2026-10-09T11:33:47.370227+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>a-blog cms provided by appleple inc. contains multiple vulnerabilities listed below.

&lt;ul&gt;
&lt;li&gt;Path traversal (CWE-22)&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;CVE-2025-27566&lt;/li&gt;
&lt;li&gt;This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege&lt;/li&gt;
&lt;/ul&gt;

&lt;li&gt;Cross-site scripting (CWE-79)&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;CVE-2025-32999&lt;/li&gt;
&lt;li&gt;This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges&lt;/li&gt;
&lt;/ul&gt;

&lt;li&gt;Server-side request forgery (CWE-918)&lt;/li&gt;
&lt;ul&gt;&lt;li&gt;CVE-2025-36560&lt;/li&gt;&lt;/ul&gt;

&lt;li&gt;Improper output neutralization for logs (CWE-117)&lt;/li&gt;
&lt;ul&gt;&lt;li&gt;CVE-2025-41429&lt;/li&gt;&lt;/ul&gt;

CVE-2025-27566, CVE-2025-32999
haidv35 (Dinh Viet Hai) reported these vulnerabilities to the developer and coordinated. After the coordination was completed, haidv35 (Dinh Viet Hai) reported the case to JPCERT/CC to notify users of the solution through JVN.

CVE-2025-36560, CVE-2025-41429
vcth4nh from VCSLab of Viettel Cyber Security (Vu Chi Thanh) reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2025-005050"/>
  </entry>
</feed>
