<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 21:37:32 +0000</lastBuildDate>
    <item>
      <title>cnvd-2018-03761</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-03761</link>
      <description>cnvd-2018-03761</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-03761</guid>
    </item>
    <item>
      <title>EUVD-2026-183050</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-183050</link>
      <description>EUVD-2026-183050</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-183050</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1287</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1287</link>
      <description>&lt;p&gt;In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1287</guid>
    </item>
    <item>
      <title>GHSA-j7j7-g4ww-pxg5 — Missing certificate validation in Apache JMeter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j7j7-g4ww-pxg5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.jmeter:ApacheJMeter&lt;/p&gt;
&lt;p&gt;In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code. This only affect those running in Distributed mode.&lt;/p&gt;
&lt;p&gt;In distributed mode, JMeter makes an architectural assumption that it is operating on a &amp;#39;safe&amp;#39; network. i.e. everyone with access to the network is considered trusted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.jmeter:ApacheJMeter&lt;/p&gt;
&lt;p&gt;In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code. This only affect those running in Distributed mode.&lt;/p&gt;
&lt;p&gt;In distributed mode, JMeter makes an architectural assumption that it is operating on a &amp;#39;safe&amp;#39; network. i.e. everyone with access to the network is considered trusted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j7j7-g4ww-pxg5</guid>
    </item>
    <item>
      <title>gsd-2018-1287</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1287</link>
      <description>gsd-2018-1287</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1287</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1287</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1287</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jakarta-jmeter, Ubuntu:18.04:LTS: jakarta-jmeter, Ubuntu:20.04:LTS: jakarta-jmeter, Ubuntu:22.04:LTS: jakarta-jmeter, Ubuntu:24.04:LTS: jakarta-jmeter, Ubuntu:25.10: jakarta-jmeter, Ubuntu:26.04:LTS: jakarta-jmeter&lt;/p&gt;
&lt;p&gt;In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: jakarta-jmeter, Ubuntu:18.04:LTS: jakarta-jmeter, Ubuntu:20.04:LTS: jakarta-jmeter, Ubuntu:22.04:LTS: jakarta-jmeter, Ubuntu:24.04:LTS: jakarta-jmeter, Ubuntu:25.10: jakarta-jmeter, Ubuntu:26.04:LTS: jakarta-jmeter&lt;/p&gt;
&lt;p&gt;In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1287</guid>
    </item>
  </channel>
</rss>
