<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:46:36 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00276</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00276</link>
      <description>bdu:2022-00276</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00276</guid>
    </item>
    <item>
      <title>certfr-2021-avi-556 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-556</link>
      <description>certfr-2021-avi-556</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-556</guid>
    </item>
    <item>
      <title>cnvd-2021-14153</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-14153</link>
      <description>cnvd-2021-14153</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-14153</guid>
    </item>
    <item>
      <title>EUVD-2026-41003</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-41003</link>
      <description>EUVD-2026-41003</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-41003</guid>
    </item>
    <item>
      <title>fkie_cve-2020-11988</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11988</link>
      <description>&lt;p&gt;Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-11988</guid>
    </item>
    <item>
      <title>GHSA-fmj2-7wx8-qj4v — Server-side request forgery (SSRF) in Apache XmlGraphics Commons</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fmj2-7wx8-qj4v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.xmlgraphics:xmlgraphics-commons&lt;/p&gt;
&lt;p&gt;Apache XmlGraphics Commons 2.4 is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.xmlgraphics:xmlgraphics-commons&lt;/p&gt;
&lt;p&gt;Apache XmlGraphics Commons 2.4 is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fmj2-7wx8-qj4v</guid>
    </item>
    <item>
      <title>gsd-2020-11988</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-11988</link>
      <description>gsd-2020-11988</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-11988</guid>
    </item>
    <item>
      <title>OESA-2022-1649 — xmlgraphics-commons security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1649</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xmlgraphics-commons, openEuler:20.03-LTS-SP3: xmlgraphics-commons, openEuler:22.03-LTS: xmlgraphics-commons&lt;/p&gt;
&lt;p&gt;Apache XML Graphics Commons is a library that consists of several reusable components used by Apache Batik and Apache FOP. Many of these components can easily be used separately outside the domains of SVG and XSL-FO. You will find components such as a PDF library, an RTF library, Graphics2D implementations that let you generate PDF and PostScript files, and much more. The Apache™ XML Graphics Commons project is part of the Apache™ Software Foundation, which is a wider community of users and developers of open source projects.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.(CVE-2020-11988)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xmlgraphics-commons, openEuler:20.03-LTS-SP3: xmlgraphics-commons, openEuler:22.03-LTS: xmlgraphics-commons&lt;/p&gt;
&lt;p&gt;Apache XML Graphics Commons is a library that consists of several reusable components used by Apache Batik and Apache FOP. Many of these components can easily be used separately outside the domains of SVG and XSL-FO. You will find components such as a PDF library, an RTF library, Graphics2D implementations that let you generate PDF and PostScript files, and much more. The Apache™ XML Graphics Commons project is part of the Apache™ Software Foundation, which is a wider community of users and developers of open source projects.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.(CVE-2020-11988)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1649</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12403-1 — xmlgraphics-commons-2.6-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12403-1</link>
      <description>&lt;p&gt;xmlgraphics-commons-2.6-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmlgraphics-commons-2.6-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12403-1</guid>
    </item>
    <item>
      <title>RHSA-2021:2475 — Red Hat Security Advisory: Red Hat Process Automation Manager 7.11.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:2475</link>
      <description>&lt;p&gt;xmlgraphics-commons: SSRF due to improper input validation by the XMPParser jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling XStream: arbitrary file deletion on the local host when unmarshalling XStream: allow a remote attacker to cause DoS only by manipulating the processed input stream XStream: SSRF via crafted input stream XStream: arbitrary file deletion on the local host via crafted input stream XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator XStream: ReDoS vulnerability XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host XStream: Unsafe deserizaliation of com.sun.org.apache.bcel.internal.util.ClassLoader XStream: allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmlgraphics-commons: SSRF due to improper input validation by the XMPParser jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling XStream: arbitrary file deletion on the local host when unmarshalling XStream: allow a remote attacker to cause DoS only by manipulating the processed input stream XStream: SSRF via crafted input stream XStream: arbitrary file deletion on the local host via crafted input stream XStream: Unsafe deserizaliation of javax.sql.rowset.BaseRowSet XStream: Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry XStream: Unsafe deserizaliation of sun.swing.SwingLazyValue XStream: Unsafe deserizaliation of com.sun.tools.javac.processing.JavacProcessingEnvironment NameProcessIterator XStream: ReDoS vulnerability XStream: SSRF can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host XStream: Unsafe deserizaliation of com.sun.org.apache.bcel.internal.util.ClassLoader XStream: allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:2475</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3550-1 — Security update for xmlgraphics-commons</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3550-1</link>
      <description>&lt;p&gt;Security update for xmlgraphics-commons&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xmlgraphics-commons&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3550-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-11988</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11988</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: xmlgraphics-commons, Ubuntu:18.04:LTS: xmlgraphics-commons, Ubuntu:20.04:LTS: xmlgraphics-commons, Ubuntu:22.04:LTS: xmlgraphics-commons, Ubuntu:24.04:LTS: xmlgraphics-commons, Ubuntu:25.10: xmlgraphics-commons, Ubuntu:26.04:LTS: xmlgraphics-commons&lt;/p&gt;
&lt;p&gt;Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: xmlgraphics-commons, Ubuntu:18.04:LTS: xmlgraphics-commons, Ubuntu:20.04:LTS: xmlgraphics-commons, Ubuntu:22.04:LTS: xmlgraphics-commons, Ubuntu:24.04:LTS: xmlgraphics-commons, Ubuntu:25.10: xmlgraphics-commons, Ubuntu:26.04:LTS: xmlgraphics-commons&lt;/p&gt;
&lt;p&gt;Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11988</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1017 — Oracle Financial Services Applications: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1017</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1017</guid>
    </item>
  </channel>
</rss>
