<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:15:10.904249+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-274088</id>
    <title>EUVD-2026-274088</title>
    <updated>2026-10-05T22:15:10.951925+00:00</updated>
    <content>EUVD-2026-274088</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-274088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28360</id>
    <title>fkie_cve-2026-28360</title>
    <updated>2026-10-05T22:15:10.951966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-28360"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mpp2-x7wv-38hv</id>
    <title>GHSA-mpp2-x7wv-38hv — NocoDB has Plaintext Storage of Shared View Passwords</title>
    <updated>2026-10-05T22:15:10.952000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nocodb</p>
<p>### Summary
Shared view passwords were stored in plaintext in the database and compared using direct string equality.</p>
<p>### Details
The `password` column in `nc_views` stored unhashed passwords. Verification used `!==` comparison across `public-datas.service.ts`, `public-metas.service.ts`, and `calendar-datas.service.ts`.</p>
<p>### Impact
If the database is compromised, shared view passwords are immediately readable. Risk is limited to password reuse scenarios.</p>
<p>### Credit
This issue was reported by [@Tulgaaaaaaaa](https://github.com/Tulgaaaaaaaa).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mpp2-x7wv-38hv"/>
  </entry>
</feed>
