<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:05:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-11250</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-11250</link>
      <description>bdu:2025-11250</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-11250</guid>
    </item>
    <item>
      <title>certfr-2020-avi-350 — De multiples vulnérabilités ont été découvertes dans les produits SAP.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-350</link>
      <description>certfr-2020-avi-350</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-350</guid>
    </item>
    <item>
      <title>EUVD-2026-71224</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-71224</link>
      <description>EUVD-2026-71224</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-71224</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1000632</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000632</link>
      <description>&lt;p&gt;dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000632</guid>
    </item>
    <item>
      <title>GHSA-6pcc-3rfx-4gpm — Dom4j contains a XML Injection vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6pcc-3rfx-4gpm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.dom4j:dom4j, Maven: dom4j:dom4j&lt;/p&gt;
&lt;p&gt;dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.&lt;/p&gt;
&lt;p&gt;Note: This advisory applies to `dom4j:dom4j` version 1.x legacy artifacts.  To resolve this a change to the latest version of `org.dom4j:dom4j` is recommended.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.dom4j:dom4j, Maven: dom4j:dom4j&lt;/p&gt;
&lt;p&gt;dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.&lt;/p&gt;
&lt;p&gt;Note: This advisory applies to `dom4j:dom4j` version 1.x legacy artifacts.  To resolve this a change to the latest version of `org.dom4j:dom4j` is recommended.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6pcc-3rfx-4gpm</guid>
    </item>
    <item>
      <title>gsd-2018-1000632</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1000632</link>
      <description>gsd-2018-1000632</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1000632</guid>
    </item>
    <item>
      <title>openSUSE-SU-2018:4045-1 — Security update for dom4j</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2018:4045-1</link>
      <description>&lt;p&gt;Security update for dom4j&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for dom4j&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2018:4045-1</guid>
    </item>
    <item>
      <title>RHEA-2019:1119 — Red Hat Enhancement Advisory: rhvm-appliance security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhea-2019:1119</link>
      <description>&lt;p&gt;undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhea-2019:1119</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:2861-1 — Security update for dom4j</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:2861-1</link>
      <description>&lt;p&gt;Security update for dom4j&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for dom4j&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:2861-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1000632</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000632</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: dom4j, Ubuntu:16.04:LTS: dom4j, Ubuntu:18.04:LTS: dom4j&lt;/p&gt;
&lt;p&gt;dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: dom4j, Ubuntu:16.04:LTS: dom4j, Ubuntu:18.04:LTS: dom4j&lt;/p&gt;
&lt;p&gt;dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000632</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0068 — IBM Business Automation Workflow: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0068</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Business Automation Workflow ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Business Automation Workflow ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0068</guid>
    </item>
  </channel>
</rss>
