<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:29:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-01050</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01050</link>
      <description>bdu:2021-01050</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01050</guid>
    </item>
    <item>
      <title>certfr-2022-avi-090 — De multiples vulnérabilités ont été découvertes dans Foxit PDF Reader et
Foxit PDF Editor. Certaines d'entre elles perm…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-090</link>
      <description>certfr-2022-avi-090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-090</guid>
    </item>
    <item>
      <title>cnvd-2020-32847</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-32847</link>
      <description>cnvd-2020-32847</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-32847</guid>
    </item>
    <item>
      <title>EUVD-2026-61121</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-61121</link>
      <description>EUVD-2026-61121</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-61121</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1285</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1285</link>
      <description>&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1285</guid>
    </item>
    <item>
      <title>GHSA-2cwj-8chv-9pp9 — XML External Entity attack in log4net</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2cwj-8chv-9pp9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: log4net&lt;/p&gt;
&lt;p&gt;Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: log4net&lt;/p&gt;
&lt;p&gt;Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2cwj-8chv-9pp9</guid>
    </item>
    <item>
      <title>gsd-2018-1285</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1285</link>
      <description>gsd-2018-1285</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1285</guid>
    </item>
    <item>
      <title>ICSA-24-226-02 — Rockwell Automation AADvance Standalone OPC-DA Server</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-226-02</link>
      <description>&lt;p&gt;An arbitrary code execution vulnerability exists in the affected product. The log4net config file does not disable XML external entities.  An arbitrary code execution vulnerability exists in the affected product. The vulnerability occurs due to a vulnerable component, the format string in log4net.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An arbitrary code execution vulnerability exists in the affected product. The log4net config file does not disable XML external entities.  An arbitrary code execution vulnerability exists in the affected product. The vulnerability occurs due to a vulnerable component, the format string in log4net.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-226-02</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12311-1 — log4net-1.2.10-78.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12311-1</link>
      <description>&lt;p&gt;log4net-1.2.10-78.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;log4net-1.2.10-78.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12311-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1285</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1285</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: log4net, Ubuntu:18.04:LTS: log4net, Ubuntu:20.04:LTS: log4net, Ubuntu:22.04:LTS: log4net&lt;/p&gt;
&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: log4net, Ubuntu:18.04:LTS: log4net, Ubuntu:20.04:LTS: log4net, Ubuntu:22.04:LTS: log4net&lt;/p&gt;
&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1285</guid>
    </item>
    <item>
      <title>VDE-2021-041 — Pepperl+Fuchs: Multiple DTM and VisuNet Software affected by log4net vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-041</link>
      <description>&lt;p&gt;Critical vulnerabilities have been discovered in the utilized component log4net by Apache Software Foundation.&lt;/p&gt;
&lt;p&gt;UPDATE A: Remediation: added fixed VisuNet Products&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities have been discovered in the utilized component log4net by Apache Software Foundation.&lt;/p&gt;
&lt;p&gt;UPDATE A: Remediation: added fixed VisuNet Products&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-041</guid>
    </item>
    <item>
      <title>VDE-2024-004 — TRUMPF: Multiple products affected by log4net vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-004</link>
      <description>&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-004</guid>
    </item>
  </channel>
</rss>
