<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 13:26:17 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-03898</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-03898</link>
      <description>bdu:2020-03898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-03898</guid>
    </item>
    <item>
      <title>EUVD-2026-40108</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-40108</link>
      <description>EUVD-2026-40108</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-40108</guid>
    </item>
    <item>
      <title>fkie_cve-2020-10780</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10780</link>
      <description>&lt;p&gt;Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-10780</guid>
    </item>
    <item>
      <title>gsd-2020-10780</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-10780</link>
      <description>gsd-2020-10780</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-10780</guid>
    </item>
    <item>
      <title>RHSA-2020:3358 — Red Hat Security Advisory: CloudForms 5.0.7 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3358</link>
      <description>&lt;p&gt;CloudForms: Cross Site Scripting in report menu title / HTML Code Injection CloudForms: Business logic bypass through widgets CloudForms: Missing functional level access control &amp;amp; IDOR lead to compromise CloudForms: CSV Injection in Orchestration Templates CloudForms: Missing access control leads to escalation of admin group privileges CloudForms: Server-Side Request Forgery (SSRF) in Ansible Tower Provider CloudForms: Out-of-band OS Command Injection through conversion host CloudForms: User Impersonation in the API for OIDC and SAML&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CloudForms: Cross Site Scripting in report menu title / HTML Code Injection CloudForms: Business logic bypass through widgets CloudForms: Missing functional level access control &amp;amp; IDOR lead to compromise CloudForms: CSV Injection in Orchestration Templates CloudForms: Missing access control leads to escalation of admin group privileges CloudForms: Server-Side Request Forgery (SSRF) in Ansible Tower Provider CloudForms: Out-of-band OS Command Injection through conversion host CloudForms: User Impersonation in the API for OIDC and SAML&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3358</guid>
    </item>
  </channel>
</rss>
