<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:23:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-105611</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-105611</link>
      <description>EUVD-2026-105611</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-105611</guid>
    </item>
    <item>
      <title>fkie_cve-2013-1768</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2013-1768</link>
      <description>&lt;p&gt;The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2013-1768</guid>
    </item>
    <item>
      <title>GHSA-j65f-mvgw-prp2 — Deserialization of Untrusted Data in Apache OpenJPA</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j65f-mvgw-prp2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.openjpa:openjpa&lt;/p&gt;
&lt;p&gt;The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.openjpa:openjpa&lt;/p&gt;
&lt;p&gt;The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j65f-mvgw-prp2</guid>
    </item>
    <item>
      <title>gsd-2013-1768</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2013-1768</link>
      <description>gsd-2013-1768</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2013-1768</guid>
    </item>
    <item>
      <title>RHSA-2013:1185 — Red Hat Security Advisory: Red Hat JBoss Fuse 6.0.0 patch 2</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2013:1185</link>
      <description>&lt;p&gt;rubygem-json: Denial of Service and SQL Injection openjpa: Remote arbitrary code execution by creating a serialized object and leveraging improperly secured server programs ruby: entity expansion DoS vulnerability in REXML apache-cxf: Multiple denial of service flaws in the StAX parser&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-json: Denial of Service and SQL Injection openjpa: Remote arbitrary code execution by creating a serialized object and leveraging improperly secured server programs ruby: entity expansion DoS vulnerability in REXML apache-cxf: Multiple denial of service flaws in the StAX parser&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2013:1185</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2013-1768</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-1768</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openjpa, Ubuntu:16.04:LTS: openjpa&lt;/p&gt;
&lt;p&gt;The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: openjpa, Ubuntu:16.04:LTS: openjpa&lt;/p&gt;
&lt;p&gt;The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-1768</guid>
    </item>
  </channel>
</rss>
