<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:00:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03074</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03074</link>
      <description>bdu:2023-03074</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03074</guid>
    </item>
    <item>
      <title>cnvd-2020-19561</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-19561</link>
      <description>cnvd-2020-19561</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-19561</guid>
    </item>
    <item>
      <title>EUVD-2026-59062</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-59062</link>
      <description>EUVD-2026-59062</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-59062</guid>
    </item>
    <item>
      <title>fkie_cve-2019-19090</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-19090</link>
      <description>&lt;p&gt;For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-19090</guid>
    </item>
    <item>
      <title>GHSA-w59j-v3f8-jgj6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w59j-v3f8-jgj6</link>
      <description>&lt;p&gt;For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w59j-v3f8-jgj6</guid>
    </item>
    <item>
      <title>gsd-2019-19090</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-19090</link>
      <description>gsd-2019-19090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-19090</guid>
    </item>
    <item>
      <title>ICSA-20-072-01 — ICSA-20-072-01_ABB eSOMS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-20-072-01</link>
      <description>&lt;p&gt;For ABB eSOMS 6.0.3 and earlier, The Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.CVE-2019-19000 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). For ABB eSOMS Versions 6.0.2 and earlier, the X-Frame-Options header is not configured in HTTP response. This can potentially allow &amp;#39;ClickJacking&amp;#39; attacks where an attacker can frame parts of the application on a malicious website, revealing sensitive user information such as authentication credentials. CVE-2019-19001 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). For ABB eSOMS Versions 6.0.2 and earlier, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of cross-site scripting. CVE-2019-19002 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N). For ABB eSOMS Versions 6.0.2 and earlier, the HTTPOnly flag is not set. This can allow JavaScript to access the cookie contents, which in turn might enable Cross-site Scripting. CVE-2019-19003 has been assigned to this vul…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For ABB eSOMS 6.0.3 and earlier, The Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.CVE-2019-19000 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). For ABB eSOMS Versions 6.0.2 and earlier, the X-Frame-Options header is not configured in HTTP response. This can potentially allow &amp;#39;ClickJacking&amp;#39; attacks where an attacker can frame parts of the application on a malicious website, revealing sensitive user information such as authentication credentials. CVE-2019-19001 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). For ABB eSOMS Versions 6.0.2 and earlier, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of cross-site scripting. CVE-2019-19002 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N). For ABB eSOMS Versions 6.0.2 and earlier, the HTTPOnly flag is not set. This can allow JavaScript to access the cookie contents, which in turn might enable Cross-site Scripting. CVE-2019-19003 has been assigned to this vul…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-20-072-01</guid>
    </item>
  </channel>
</rss>
