<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:51:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-02137</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-02137</link>
      <description>bdu:2020-02137</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-02137</guid>
    </item>
    <item>
      <title>certfr-2020-avi-433 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-433</link>
      <description>certfr-2020-avi-433</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-433</guid>
    </item>
    <item>
      <title>cnvd-2020-22364</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-22364</link>
      <description>cnvd-2020-22364</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-22364</guid>
    </item>
    <item>
      <title>EUVD-2026-195659</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-195659</link>
      <description>EUVD-2026-195659</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-195659</guid>
    </item>
    <item>
      <title>fkie_cve-2019-13990</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-13990</link>
      <description>&lt;p&gt;initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-13990</guid>
    </item>
    <item>
      <title>GHSA-9qcf-c26r-x5rf — XML external entity injection in Terracotta Quartz Scheduler</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9qcf-c26r-x5rf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.quartz-scheduler:quartz&lt;/p&gt;
&lt;p&gt;initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.quartz-scheduler:quartz&lt;/p&gt;
&lt;p&gt;initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9qcf-c26r-x5rf</guid>
    </item>
    <item>
      <title>gsd-2019-13990</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-13990</link>
      <description>gsd-2019-13990</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-13990</guid>
    </item>
    <item>
      <title>RHSA-2020:3196 — Red Hat Security Advisory: Red Hat Decision Manager 7.8.0 Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3196</link>
      <description>&lt;p&gt;HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth HTTP/2: flood using empty frames results in excessive resource consumption cxf: does not restrict the number of message attachments cxf: OpenId Connect token service does not properly validate the clientId libquartz: XXE attacks via job description netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers cxf: reflected XSS in the services listing page jackson-databind: lacks certain net.sf.ehcache blocking netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header keycloak: security issue on reset credential flow netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProvide…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth HTTP/2: flood using SETTINGS frames results in unbounded memory growth HTTP/2: flood using empty frames results in excessive resource consumption cxf: does not restrict the number of message attachments cxf: OpenId Connect token service does not properly validate the clientId libquartz: XXE attacks via job description netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers cxf: reflected XSS in the services listing page jackson-databind: lacks certain net.sf.ehcache blocking netty: HTTP request smuggling netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header keycloak: security issue on reset credential flow netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling jackson-databind: Lacks certain xbean-reflect/JNDI blocking jackson-databind: Serialization gadgets in shaded-hikari-config jackson-databind: Serialization gadgets in ibatis-sqlmap jackson-databind: Serialization gadgets in anteros-core jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProvide…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3196</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:0984-1 — Security update for quartz</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:0984-1</link>
      <description>&lt;p&gt;Security update for quartz&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for quartz&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:0984-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-13990</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-13990</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libquartz-java, Ubuntu:18.04:LTS: libquartz-java, Ubuntu:18.04:LTS: libquartz2-java, Ubuntu:20.04:LTS: libquartz-java, Ubuntu:20.04:LTS: libquartz2-java, Ubuntu:22.04:LTS: libquartz-java, Ubuntu:24.04:LTS: libquartz-java, Ubuntu:25.10: libquartz-java, Ubuntu:26.04:LTS: libquartz-java&lt;/p&gt;
&lt;p&gt;initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libquartz-java, Ubuntu:18.04:LTS: libquartz-java, Ubuntu:18.04:LTS: libquartz2-java, Ubuntu:20.04:LTS: libquartz-java, Ubuntu:20.04:LTS: libquartz2-java, Ubuntu:22.04:LTS: libquartz-java, Ubuntu:24.04:LTS: libquartz-java, Ubuntu:25.10: libquartz-java, Ubuntu:26.04:LTS: libquartz-java&lt;/p&gt;
&lt;p&gt;initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-13990</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2700 — Atlassian Confluence: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2700</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Atlassian Confluence, Atlassian Jira Software, Atlassian Bitbucket und Atlassian Bamboo ausnutzen, um Administratorrechte zu erlangen, Informationen offenzulegen, beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Atlassian Confluence, Atlassian Jira Software, Atlassian Bitbucket und Atlassian Bamboo ausnutzen, um Administratorrechte zu erlangen, Informationen offenzulegen, beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2700</guid>
    </item>
  </channel>
</rss>
