<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T18:14:07.177916+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2025-028</id>
    <title>DRUPAL-CONTRIB-2025-028</title>
    <updated>2026-10-07T18:14:07.241996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/access_code</p>
<p>This module enables users to log in using a short access code instead of providing a username/password combination.</p>
<p>The module doesn't sufficiently protect against brute force attacks to guess a user's access code.</p>
<p>This vulnerability is mitigated by the fact that access code based logins are off by default and only enabled for accounts that enable it. Sites could mitigate the issue without updating by:</p>
<p>1. disabling the access code login method for critical accounts
2. monitor and prevent brute force attacks in other ways (for example, with a Web Application Firewall)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2025-028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-229806</id>
    <title>EUVD-2026-229806</title>
    <updated>2026-10-07T18:14:07.242055+00:00</updated>
    <content>EUVD-2026-229806</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-229806"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-3129</id>
    <title>fkie_cve-2025-3129</title>
    <updated>2026-10-07T18:14:07.242072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-3129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9qmr-4gv6-xmf3</id>
    <title>GHSA-9qmr-4gv6-xmf3</title>
    <updated>2026-10-07T18:14:07.242094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9qmr-4gv6-xmf3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0690</id>
    <title>WID-SEC-W-2025-0690 — Drupal: Mehrere Schwachstellen</title>
    <updated>2026-10-07T18:14:07.242109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um Sicherheitsmaßnahmen zu umgehen und Cross-Site-Scripting-Schwachstellen auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0690"/>
  </entry>
</feed>
