<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 20:47:06 +0000</lastBuildDate>
    <item>
      <title>cnvd-2018-20454</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-20454</link>
      <description>cnvd-2018-20454</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-20454</guid>
    </item>
    <item>
      <title>EUVD-2026-167076</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-167076</link>
      <description>EUVD-2026-167076</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-167076</guid>
    </item>
    <item>
      <title>fkie_cve-2018-17917</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-17917</link>
      <description>&lt;p&gt;All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-17917</guid>
    </item>
    <item>
      <title>GHSA-hx93-w6p2-8rvj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hx93-w6p2-8rvj</link>
      <description>&lt;p&gt;All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hx93-w6p2-8rvj</guid>
    </item>
    <item>
      <title>gsd-2018-17917</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-17917</link>
      <description>gsd-2018-17917</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-17917</guid>
    </item>
    <item>
      <title>ICSA-18-282-06 — Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-18-282-06</link>
      <description>&lt;p&gt;An attacker may be able to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.CVE-2018-17917 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). An attacker could use an undocumented user account default with its default password to login to XMeye and access/view video streams.CVE-2018-17919 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Not all device communication is encrypted. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code.CVE-2018-17915 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker may be able to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.CVE-2018-17917 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). An attacker could use an undocumented user account default with its default password to login to XMeye and access/view video streams.CVE-2018-17919 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Not all device communication is encrypted. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code.CVE-2018-17915 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-18-282-06</guid>
    </item>
  </channel>
</rss>
