<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:11:36 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-04661</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-04661</link>
      <description>cnvd-2020-04661</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-04661</guid>
    </item>
    <item>
      <title>EUVD-2026-35568</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35568</link>
      <description>EUVD-2026-35568</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35568</guid>
    </item>
    <item>
      <title>fkie_cve-2020-1697</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1697</link>
      <description>&lt;p&gt;It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-1697</guid>
    </item>
    <item>
      <title>GHSA-8vf3-4w62-m3pq — XSS in Keycloak</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8vf3-4w62-m3pq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8vf3-4w62-m3pq</guid>
    </item>
    <item>
      <title>gsd-2020-1697</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-1697</link>
      <description>gsd-2020-1697</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-1697</guid>
    </item>
    <item>
      <title>RHSA-2020:0445 — Red Hat Security Advisory: Red Hat Single Sign-On 7.3.6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:0445</link>
      <description>&lt;p&gt;xstream: remote code execution due to insecure XML deserialization (regression of  CVE-2013-7285) hibernate-validator: safeHTML validator allows XSS jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS jackson-databind: Serialization gadgets in classes of the commons-configuration package jackson-databind: Serialization gadgets in classes of the xalan package jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in classes of the ehcache package jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.* keycloak: stored XSS in client settings via application links&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xstream: remote code execution due to insecure XML deserialization (regression of  CVE-2013-7285) hibernate-validator: safeHTML validator allows XSS jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS jackson-databind: Serialization gadgets in classes of the commons-configuration package jackson-databind: Serialization gadgets in classes of the xalan package jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariDataSource netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers jackson-databind: Serialization gadgets in org.apache.commons.dbcp.datasources.* jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource jackson-databind: Serialization gadgets in classes of the ehcache package jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.* keycloak: stored XSS in client settings via application links&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:0445</guid>
    </item>
  </channel>
</rss>
