<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:45:25.366950+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331828</id>
    <title>EUVD-2026-331828</title>
    <updated>2026-10-06T18:45:25.420473+00:00</updated>
    <content>EUVD-2026-331828</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331828"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50040</id>
    <title>fkie_cve-2026-50040</title>
    <updated>2026-10-06T18:45:25.420511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Storage Concentrator (SC &amp; SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8h25-3425-5fgh</id>
    <title>GHSA-8h25-3425-5fgh</title>
    <updated>2026-10-06T18:45:25.420548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Storage Concentrator (SC &amp; SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8h25-3425-5fgh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-181-06</id>
    <title>ICSA-26-181-06 — StoneFly Storage Concentrator</title>
    <updated>2026-10-06T18:45:25.420588+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Storage Concentrator (SC &amp; SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of internal services, including database accounts, licensing, replication services, and third-party integrations, meaning successful exploitation of this vulnerability could provide an attacker with unauthorized access to multiple interconnected systems. Storage Concentrator (SC &amp; SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges. Storage Concentrator (SC &amp; SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system. Storage Concentrator (SC &amp; SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-181-06"/>
  </entry>
</feed>
