<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T07:51:44.930761+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329247</id>
    <title>EUVD-2026-329247</title>
    <updated>2026-10-06T07:51:44.975294+00:00</updated>
    <content>EUVD-2026-329247</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48067</id>
    <title>fkie_cve-2026-48067</title>
    <updated>2026-10-06T07:51:44.975329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from filament/tables 3.0.0 until 3.3.51, the recordSelectOptionsQuery() method may be used to scope the options available in the Select field for AttachAction and AssociateAction. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value. This vulnerability is fixed in filament/actions  4.11.4 and 5.6.4 and filament/tables 3.3.51.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7q3w-xqjw-g3cr</id>
    <title>GHSA-7q3w-xqjw-g3cr — Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields</title>
    <updated>2026-10-06T07:51:44.975365+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: filament/tables, Packagist: filament/actions</p>
<p>The `recordSelectOptionsQuery()` method may be used to scope the options available in the `Select` field for `AttachAction` and `AssociateAction`. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7q3w-xqjw-g3cr"/>
  </entry>
</feed>
