<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:01:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00278</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00278</link>
      <description>bdu:2022-00278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00278</guid>
    </item>
    <item>
      <title>certfr-2022-avi-928 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-928</link>
      <description>certfr-2022-avi-928</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-928</guid>
    </item>
    <item>
      <title>EUVD-2026-215921</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215921</link>
      <description>EUVD-2026-215921</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215921</guid>
    </item>
    <item>
      <title>fkie_cve-2020-13936</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13936</link>
      <description>&lt;p&gt;An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-13936</guid>
    </item>
    <item>
      <title>GHSA-59j4-wjwp-mw9m — Sandbox Bypass in Apache Velocity Engine</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-59j4-wjwp-mw9m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.velocity:velocity-engine-parent, Maven: org.apache.velocity:velocity&lt;/p&gt;
&lt;p&gt;An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.velocity:velocity-engine-parent, Maven: org.apache.velocity:velocity&lt;/p&gt;
&lt;p&gt;An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-59j4-wjwp-mw9m</guid>
    </item>
    <item>
      <title>gsd-2020-13936</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-13936</link>
      <description>gsd-2020-13936</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-13936</guid>
    </item>
    <item>
      <title>OESA-2021-1157 — velocity security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1157</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: velocity&lt;/p&gt;
&lt;p&gt;Velocity is a Java-based template engine. It permits anyone to use the simple yet powerful template language to reference objects defined in Java code.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.(CVE-2020-13936)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: velocity&lt;/p&gt;
&lt;p&gt;Velocity is a Java-based template engine. It permits anyone to use the simple yet powerful template language to reference objects defined in Java code.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.(CVE-2020-13936)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1157</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0447-1 — Security update for velocity</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0447-1</link>
      <description>&lt;p&gt;Security update for velocity&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for velocity&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0447-1</guid>
    </item>
    <item>
      <title>RHSA-2021:2046 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.7 security update on RHEL 6</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:2046</link>
      <description>&lt;p&gt;velocity: arbitrary code execution when attacker is able to modify templates netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;velocity: arbitrary code execution when attacker is able to modify templates netty: Information disclosure via the local system temporary directory netty: possible request smuggling in HTTP/2 due missing validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:2046</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:0800-1 — Security update for velocity</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:0800-1</link>
      <description>&lt;p&gt;Security update for velocity&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for velocity&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:0800-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-13936</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13936</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: velocity, Ubuntu:Pro:18.04:LTS: velocity, Ubuntu:20.04:LTS: velocity&lt;/p&gt;
&lt;p&gt;An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: velocity, Ubuntu:Pro:18.04:LTS: velocity, Ubuntu:20.04:LTS: velocity&lt;/p&gt;
&lt;p&gt;An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13936</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0809 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</guid>
    </item>
  </channel>
</rss>
