<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:06:10 +0000</lastBuildDate>
    <item>
      <title>certfr-2023-avi-0701 — De multiples vulnérabilités ont été découvertes dans Splunk. Certaines
d'entre elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0701</link>
      <description>certfr-2023-avi-0701</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0701</guid>
    </item>
    <item>
      <title>cnvd-2021-39695</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-39695</link>
      <description>cnvd-2021-39695</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-39695</guid>
    </item>
    <item>
      <title>EUVD-2026-291519</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291519</link>
      <description>EUVD-2026-291519</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291519</guid>
    </item>
    <item>
      <title>fkie_cve-2018-20225</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-20225</link>
      <description>&lt;p&gt;An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-20225</guid>
    </item>
    <item>
      <title>GHSA-7p5p-7qq5-cc86</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7p5p-7qq5-cc86</link>
      <description>&lt;p&gt;An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7p5p-7qq5-cc86</guid>
    </item>
    <item>
      <title>gsd-2018-20225</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-20225</link>
      <description>gsd-2018-20225</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-20225</guid>
    </item>
    <item>
      <title>msrc_CVE-2018-20225 — An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2018-20225</link>
      <description>msrc_CVE-2018-20225</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2018-20225</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-20225</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-20225</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:Pro:20.04:LTS: python-pip&lt;/p&gt;
&lt;p&gt;An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:Pro:20.04:LTS: python-pip&lt;/p&gt;
&lt;p&gt;An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-20225</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2229 — Splunk Splunk Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2229</link>
      <description>&lt;p&gt;Ein entfernter, authentifizierter Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise ausnutzen, um beliebigen Code auszuführen, einen &amp;#39;Denial of Service&amp;#39;-Zustand zu verursachen, seine Privilegien zu erweitern und weitere, nicht spezifizierte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentifizierter Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise ausnutzen, um beliebigen Code auszuführen, einen &amp;#39;Denial of Service&amp;#39;-Zustand zu verursachen, seine Privilegien zu erweitern und weitere, nicht spezifizierte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2229</guid>
    </item>
  </channel>
</rss>
