<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:15:40 +0000</lastBuildDate>
    <item>
      <title>cnvd-2016-11232</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-11232</link>
      <description>cnvd-2016-11232</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-11232</guid>
    </item>
    <item>
      <title>EUVD-2026-87284</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-87284</link>
      <description>EUVD-2026-87284</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-87284</guid>
    </item>
    <item>
      <title>fkie_cve-2016-8639</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-8639</link>
      <description>&lt;p&gt;It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-8639</guid>
    </item>
    <item>
      <title>GHSA-mwqr-rg79-hjrr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mwqr-rg79-hjrr</link>
      <description>&lt;p&gt;It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mwqr-rg79-hjrr</guid>
    </item>
    <item>
      <title>gsd-2016-8639</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-8639</link>
      <description>gsd-2016-8639</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-8639</guid>
    </item>
    <item>
      <title>RHSA-2018:0336 — Red Hat Security Advisory: Satellite 6.3 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:0336</link>
      <description>&lt;p&gt;rubygem-will_paginate: XSS vulnerabilities foreman: models with a &amp;#39;belongs_to&amp;#39; association to an Organization do not verify association belongs to that Organization V8: integer overflow leading to buffer overflow in Zone::New foreman: inspect in a provisioning template exposes sensitive controller information pulp: Leakage of CA key in pulp-qpid-ssl-cfg pulp: Unsafe use of bash $RANDOM for NSS DB password and seed foreman: privilege escalation through Organization and Locations API foreman: Information disclosure in provisioning template previews foreman: inside discovery-debug, the root password is displayed in plaintext foreman: Persistent XSS in Foreman remote execution plugin foreman: Foreman information leak through unauthorized multiple_checkboxes helper foreman: Information leak through organizations and locations feature foreman: Stored XSS vulnerability in remote execution plugin foreman: Stored XSS in org/loc wizard foreman: Stored XSS via organization/location with HTML in name foreman-debug: missing obfuscation of sensitive information katello-debug: Possible symlink attacks due to use of predictable file names puppet: Unsafe YAML deserialization rubygem-hammer_cli: no verification of API server&amp;#39;s SSL certificate foreman: Image password leak Interconnect: Denial of Service vulnerability in Red Hat JBoss AMQ Interconnect katello: SQL inject in errata-related REST API&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-will_paginate: XSS vulnerabilities foreman: models with a &amp;#39;belongs_to&amp;#39; association to an Organization do not verify association belongs to that Organization V8: integer overflow leading to buffer overflow in Zone::New foreman: inspect in a provisioning template exposes sensitive controller information pulp: Leakage of CA key in pulp-qpid-ssl-cfg pulp: Unsafe use of bash $RANDOM for NSS DB password and seed foreman: privilege escalation through Organization and Locations API foreman: Information disclosure in provisioning template previews foreman: inside discovery-debug, the root password is displayed in plaintext foreman: Persistent XSS in Foreman remote execution plugin foreman: Foreman information leak through unauthorized multiple_checkboxes helper foreman: Information leak through organizations and locations feature foreman: Stored XSS vulnerability in remote execution plugin foreman: Stored XSS in org/loc wizard foreman: Stored XSS via organization/location with HTML in name foreman-debug: missing obfuscation of sensitive information katello-debug: Possible symlink attacks due to use of predictable file names puppet: Unsafe YAML deserialization rubygem-hammer_cli: no verification of API server&amp;#39;s SSL certificate foreman: Image password leak Interconnect: Denial of Service vulnerability in Red Hat JBoss AMQ Interconnect katello: SQL inject in errata-related REST API&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:0336</guid>
    </item>
  </channel>
</rss>
