<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:57:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-04013</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-04013</link>
      <description>bdu:2020-04013</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-04013</guid>
    </item>
    <item>
      <title>EUVD-2026-41964</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-41964</link>
      <description>EUVD-2026-41964</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-41964</guid>
    </item>
    <item>
      <title>fkie_cve-2020-13699</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13699</link>
      <description>&lt;p&gt;TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-13699</guid>
    </item>
    <item>
      <title>GHSA-f43w-mfrf-mv66</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f43w-mfrf-mv66</link>
      <description>&lt;p&gt;TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f43w-mfrf-mv66</guid>
    </item>
    <item>
      <title>gsd-2020-13699</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-13699</link>
      <description>gsd-2020-13699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-13699</guid>
    </item>
    <item>
      <title>ICSA-21-308-01 — VISAM VBASE Editor</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-308-01</link>
      <description>&lt;p&gt;The affected product is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.CVE-2021-38417has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). The affected product does not neutralize or incorrectly neutralizes user-controllable input before the data is placed in output used as a public-facing webpage.CVE-2021-42535 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N). The affected software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.CVE-2021-42537 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N). The affected product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy. The following CVEs are associated with this product.CVE-2021-34803, CVE-2020-13699, CVE-2019-18988, CVE-2018-16550, CVE-2018-14333, CVE-2005-2475 have been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:L/A…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.CVE-2021-38417has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). The affected product does not neutralize or incorrectly neutralizes user-controllable input before the data is placed in output used as a public-facing webpage.CVE-2021-42535 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N). The affected software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.CVE-2021-42537 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N). The affected product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy. The following CVEs are associated with this product.CVE-2021-34803, CVE-2020-13699, CVE-2019-18988, CVE-2018-16550, CVE-2018-14333, CVE-2005-2475 have been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:L/A…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-308-01</guid>
    </item>
  </channel>
</rss>
