<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:17:42 +0000</lastBuildDate>
    <item>
      <title>cnvd-2021-18234</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-18234</link>
      <description>cnvd-2021-18234</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-18234</guid>
    </item>
    <item>
      <title>EUVD-2026-56644</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-56644</link>
      <description>EUVD-2026-56644</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-56644</guid>
    </item>
    <item>
      <title>fkie_cve-2019-14900</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-14900</link>
      <description>&lt;p&gt;A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-14900</guid>
    </item>
    <item>
      <title>GHSA-8grg-q944-cch5 — SQL Injection in Hibernate ORM</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8grg-q944-cch5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.hibernate:hibernate-core&lt;/p&gt;
&lt;p&gt;A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.hibernate:hibernate-core&lt;/p&gt;
&lt;p&gt;A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8grg-q944-cch5</guid>
    </item>
    <item>
      <title>gsd-2019-14900</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-14900</link>
      <description>gsd-2019-14900</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-14900</guid>
    </item>
    <item>
      <title>OESA-2021-1135 — hibernate security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1135</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: hibernate&lt;/p&gt;
&lt;p&gt;Hibernate is a powerful, high-performance, feature-rich and very popular ORM solution for Java. Hibernate facilitates development of persistent objects based on the common Java object model to mirror the underlying database structure. This approach progresses the business performance to some extent, advances development efficiency exceedingly and obtains preferable economical efficiency and practicability.  Provides: hibernate-core = 5.0.10-6.oe1 Provides: hibernate-c3p0 = 5.0.10-6.oe1 Provides: hibernate-ehcache = 5.0.10-6.oe1 Provides: hibernate-entitymanager = 5.0.10-6.oe1 Provides: hibernate-envers = 5.0.10-6.oe1 Provides: hibernate-hikaricp = 5.0.10-6.oe1 Provides: hibernate-infinispan = 5.0.10-6.oe1 Provides: hibernate-java8 = 5.0.10-6.oe1 Provides: hibernate-osgi = 5.0.10-6.oe1 Provides: hibernate-parent = 5.0.10-6.oe1 Provides: hibernate-proxool = 5.0.10-6.oe1 Provides: hibernate-spatial = 5.0.10-6.oe1 Provides: hibernate-testing = 5.0.10-6.oe1 Provides: hibernate-javadoc = 5.0.10-6.oe1  Obsoletes: hibernate-core &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-c3p0 &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-ehcache &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-entitymanager &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-envers &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-hikaricp &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-infinispan &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-java8 &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-osgi &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-parent &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: hibernate&lt;/p&gt;
&lt;p&gt;Hibernate is a powerful, high-performance, feature-rich and very popular ORM solution for Java. Hibernate facilitates development of persistent objects based on the common Java object model to mirror the underlying database structure. This approach progresses the business performance to some extent, advances development efficiency exceedingly and obtains preferable economical efficiency and practicability.  Provides: hibernate-core = 5.0.10-6.oe1 Provides: hibernate-c3p0 = 5.0.10-6.oe1 Provides: hibernate-ehcache = 5.0.10-6.oe1 Provides: hibernate-entitymanager = 5.0.10-6.oe1 Provides: hibernate-envers = 5.0.10-6.oe1 Provides: hibernate-hikaricp = 5.0.10-6.oe1 Provides: hibernate-infinispan = 5.0.10-6.oe1 Provides: hibernate-java8 = 5.0.10-6.oe1 Provides: hibernate-osgi = 5.0.10-6.oe1 Provides: hibernate-parent = 5.0.10-6.oe1 Provides: hibernate-proxool = 5.0.10-6.oe1 Provides: hibernate-spatial = 5.0.10-6.oe1 Provides: hibernate-testing = 5.0.10-6.oe1 Provides: hibernate-javadoc = 5.0.10-6.oe1  Obsoletes: hibernate-core &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-c3p0 &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-ehcache &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-entitymanager &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-envers &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-hikaricp &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-infinispan &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-java8 &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-osgi &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-parent &amp;amp;lt; 5.0.10-6.oe1 Obsoletes: hibernate-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1135</guid>
    </item>
    <item>
      <title>RHSA-2020:2112 — Red Hat Security Advisory: Red Hat Single Sign-On 7.3.8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:2112</link>
      <description>&lt;p&gt;jackson-mapper-asl: XML external entity similar to CVE-2016-3720 hibernate: SQL injection issue in Hibernate ORM cxf: reflected XSS in the services listing page resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class keycloak: security issue on reset credential flow Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain keycloak: problem with privacy after user logout undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass keycloak: improper verification of certificate with host mismatch could result in information disclosure cryptacular: excessive memory allocation during a decode operation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-mapper-asl: XML external entity similar to CVE-2016-3720 hibernate: SQL injection issue in Hibernate ORM cxf: reflected XSS in the services listing page resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class keycloak: security issue on reset credential flow Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain keycloak: problem with privacy after user logout undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass keycloak: improper verification of certificate with host mismatch could result in information disclosure cryptacular: excessive memory allocation during a decode operation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:2112</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:2650-1 — Security update for SUSE Manager Server 4.0</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:2650-1</link>
      <description>&lt;p&gt;Security update for SUSE Manager Server 4.0&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Server 4.0&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:2650-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1912 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1912</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um Code zur Ausführung zu bringen, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise Application Platform ausnutzen, um Code zur Ausführung zu bringen, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1912</guid>
    </item>
  </channel>
</rss>
