<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:31:09 +0000</lastBuildDate>
    <item>
      <title>certfr-2018-avi-111 — Une vulnérabilité a été découverte dans les produits Pivotal . Elle
permet à un attaquant de provoquer une exécution de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-111</link>
      <description>certfr-2018-avi-111</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-111</guid>
    </item>
    <item>
      <title>cnvd-2017-27968</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-27968</link>
      <description>cnvd-2017-27968</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-27968</guid>
    </item>
    <item>
      <title>EUVD-2026-75122</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-75122</link>
      <description>EUVD-2026-75122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-75122</guid>
    </item>
    <item>
      <title>fkie_cve-2017-8046</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-8046</link>
      <description>&lt;p&gt;Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-8046</guid>
    </item>
    <item>
      <title>GHSA-9qf9-28h9-hqcj — Remote code execution in PATCH requests in Spring Data REST</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9qf9-28h9-hqcj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.data:spring-data-rest-core&lt;/p&gt;
&lt;p&gt;Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) can use specially crafted JSON data to run arbitrary Java code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.data:spring-data-rest-core&lt;/p&gt;
&lt;p&gt;Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) can use specially crafted JSON data to run arbitrary Java code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9qf9-28h9-hqcj</guid>
    </item>
    <item>
      <title>gsd-2017-8046</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-8046</link>
      <description>gsd-2017-8046</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-8046</guid>
    </item>
    <item>
      <title>RHSA-2018:2405 — Red Hat Security Advisory: Red Hat FIS 2.0 on Fuse 6.3.0 R7 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2405</link>
      <description>&lt;p&gt;spring-boot: Malicious PATCH requests submitted to servers can use specially crafted JSON data to run arbitrary Java code undertow: Client can use bogus uri in Digest authentication spring-framework: Improper URL path validation allows for bypassing of security checks on static resources ignite: Possible Execution of Arbitrary Code Within Deserialization Endpoints spark: Absolute and relative pathnames allow for unintended static file disclosure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;spring-boot: Malicious PATCH requests submitted to servers can use specially crafted JSON data to run arbitrary Java code undertow: Client can use bogus uri in Digest authentication spring-framework: Improper URL path validation allows for bypassing of security checks on static resources ignite: Possible Execution of Arbitrary Code Within Deserialization Endpoints spark: Absolute and relative pathnames allow for unintended static file disclosure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2405</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0528 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0528</guid>
    </item>
  </channel>
</rss>
