<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:14:35 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>cnvd-2018-09638</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-09638</link>
      <description>cnvd-2018-09638</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-09638</guid>
    </item>
    <item>
      <title>EUVD-2026-164223</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-164223</link>
      <description>EUVD-2026-164223</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-164223</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1259</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1259</link>
      <description>&lt;p&gt;Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data&amp;#39;s projection-based request payload binding to access arbitrary files on the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data&amp;#39;s projection-based request payload binding to access arbitrary files on the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1259</guid>
    </item>
    <item>
      <title>GHSA-m929-7fr6-cvjg — Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper rest…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m929-7fr6-cvjg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.data:spring-data-commons&lt;/p&gt;
&lt;p&gt;Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data&amp;#39;s projection-based request payload binding to access arbitrary files on the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework.data:spring-data-commons&lt;/p&gt;
&lt;p&gt;Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data&amp;#39;s projection-based request payload binding to access arbitrary files on the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m929-7fr6-cvjg</guid>
    </item>
    <item>
      <title>gsd-2018-1259</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1259</link>
      <description>gsd-2018-1259</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1259</guid>
    </item>
    <item>
      <title>RHSA-2018:1809 — Red Hat Security Advisory: Red Hat OpenShift Application Runtimes Spring Boot security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:1809</link>
      <description>&lt;p&gt;spring-framework: ReDoS Attack with spring-messaging spring-data-commons: XXE with Spring Data’s XMLBeam integration spring-security-oauth: remote code execution in the authorization process&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;spring-framework: ReDoS Attack with spring-messaging spring-data-commons: XXE with Spring Data’s XMLBeam integration spring-security-oauth: remote code execution in the authorization process&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:1809</guid>
    </item>
  </channel>
</rss>
