<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:07:27 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-01021</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-01021</link>
      <description>bdu:2020-01021</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-01021</guid>
    </item>
    <item>
      <title>certfr-2020-avi-034 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-034</link>
      <description>certfr-2020-avi-034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-034</guid>
    </item>
    <item>
      <title>EUVD-2026-48403</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-48403</link>
      <description>EUVD-2026-48403</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-48403</guid>
    </item>
    <item>
      <title>fkie_cve-2019-0221</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-0221</link>
      <description>&lt;p&gt;The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-0221</guid>
    </item>
    <item>
      <title>GHSA-jjpq-gp5q-8q6w — Cross-site scripting in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jjpq-gp5q-8q6w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core, Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jjpq-gp5q-8q6w</guid>
    </item>
    <item>
      <title>gsd-2019-0221</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-0221</link>
      <description>gsd-2019-0221</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-0221</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:1673-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1673-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:1673-1</guid>
    </item>
    <item>
      <title>RHSA-2019:3929 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.2 security release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2019:3929</link>
      <description>&lt;p&gt;openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) tomcat: Apache Tomcat HTTP/2 DoS tomcat: XSS in SSI printenv tomcat: Remote Code Execution on Windows openssl: 0-byte record padding oracle tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) tomcat: Apache Tomcat HTTP/2 DoS tomcat: XSS in SSI printenv tomcat: Remote Code Execution on Windows openssl: 0-byte record padding oracle tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2019:3929</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:1693-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:1693-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:1693-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-0221</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0221</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat8, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat8, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat7&lt;/p&gt;
&lt;p&gt;The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-0221</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1994 — Apache Tomcat: Schwachstelle ermöglicht Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1994</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1994</guid>
    </item>
  </channel>
</rss>
