<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:32:04 +0000</lastBuildDate>
    <item>
      <title>cnvd-2015-07697</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-07697</link>
      <description>cnvd-2015-07697</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-07697</guid>
    </item>
    <item>
      <title>EUVD-2026-93301</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-93301</link>
      <description>EUVD-2026-93301</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-93301</guid>
    </item>
    <item>
      <title>fkie_cve-2015-5320</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2015-5320</link>
      <description>&lt;p&gt;Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2015-5320</guid>
    </item>
    <item>
      <title>GHSA-449q-v4j2-5h8p — Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-449q-v4j2-5h8p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jenkins-ci.main:jenkins-core&lt;/p&gt;
&lt;p&gt;Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-449q-v4j2-5h8p</guid>
    </item>
    <item>
      <title>gsd-2015-5320</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2015-5320</link>
      <description>gsd-2015-5320</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2015-5320</guid>
    </item>
    <item>
      <title>RHSA-2016:0070 — Red Hat Security Advisory: Red Hat OpenShift Enterprise 3.1.1 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:0070</link>
      <description>&lt;p&gt;commons-fileupload: Arbitrary file upload via deserialization stapler-adjunct-zeroclipboard: multiple cross-site scripting (XSS) flaws jenkins: denial of service (SECURITY-87) jenkins: username discovery (SECURITY-110) jenkins: job configuration issues (SECURITY-127, SECURITY-128) jenkins: directory traversal flaw (SECURITY-131) jenkins: remote code execution flaw (SECURITY-150) jenkins: plug-in code can be downloaded by anyone with read access (SECURITY-155) jenkins: password exposure in DOM (SECURITY-138) jenkins: cross-site scripting flaw in Jenkins core (SECURITY-143) jenkins: Combination filter Groovy script unsecured (SECURITY-125) jenkins: directory traversal from artifacts via symlink (SECURITY-162) jenkins: update center metadata retrieval DoS attack (SECURITY-163) jenkins: HudsonPrivateSecurityRealm allows creation of reserved names (SECURITY-166) jenkins: Reflective XSS vulnerability (SECURITY-171, SECURITY-177) jenkins: Reflective XSS vulnerability (SECURITY-171, SECURITY-177) jenkins: forced API token change (SECURITY-180) jenkins: Project name disclosure via fingerprints (SECURITY-153) jenkins: Public value used for CSRF protection salt (SECURITY-169) jenkins: XXE injection into job configurations via CLI (SECURITY-173) jenkins: Secret key not verified when connecting a slave (SECURITY-184) jenkins: Information disclosure via sidepanel (SECURITY-192) jenkins: Local file inclusion vulnerability (SECURITY-195) jenkins: API tokens of other users available to admin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;commons-fileupload: Arbitrary file upload via deserialization stapler-adjunct-zeroclipboard: multiple cross-site scripting (XSS) flaws jenkins: denial of service (SECURITY-87) jenkins: username discovery (SECURITY-110) jenkins: job configuration issues (SECURITY-127, SECURITY-128) jenkins: directory traversal flaw (SECURITY-131) jenkins: remote code execution flaw (SECURITY-150) jenkins: plug-in code can be downloaded by anyone with read access (SECURITY-155) jenkins: password exposure in DOM (SECURITY-138) jenkins: cross-site scripting flaw in Jenkins core (SECURITY-143) jenkins: Combination filter Groovy script unsecured (SECURITY-125) jenkins: directory traversal from artifacts via symlink (SECURITY-162) jenkins: update center metadata retrieval DoS attack (SECURITY-163) jenkins: HudsonPrivateSecurityRealm allows creation of reserved names (SECURITY-166) jenkins: Reflective XSS vulnerability (SECURITY-171, SECURITY-177) jenkins: Reflective XSS vulnerability (SECURITY-171, SECURITY-177) jenkins: forced API token change (SECURITY-180) jenkins: Project name disclosure via fingerprints (SECURITY-153) jenkins: Public value used for CSRF protection salt (SECURITY-169) jenkins: XXE injection into job configurations via CLI (SECURITY-173) jenkins: Secret key not verified when connecting a slave (SECURITY-184) jenkins: Information disclosure via sidepanel (SECURITY-192) jenkins: Local file inclusion vulnerability (SECURITY-195) jenkins: API tokens of other users available to admin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:0070</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1215 — Jenkins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1215</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder angemeldeter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um Sicherheitsfunktionen zu umgehen, einen &amp;#34;stored cross-site-scripting&amp;#34;-Angriff durchzuführen, Benutzerrechte zu erlangen und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder angemeldeter Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um Sicherheitsfunktionen zu umgehen, einen &amp;#34;stored cross-site-scripting&amp;#34;-Angriff durchzuführen, Benutzerrechte zu erlangen und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1215</guid>
    </item>
  </channel>
</rss>
