<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:09:24 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-23407</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-23407</link>
      <description>cnvd-2020-23407</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-23407</guid>
    </item>
    <item>
      <title>EUVD-2026-35648</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35648</link>
      <description>EUVD-2026-35648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35648</guid>
    </item>
    <item>
      <title>fkie_cve-2020-1728</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1728</link>
      <description>&lt;p&gt;A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-1728</guid>
    </item>
    <item>
      <title>GHSA-3gg7-9q2x-79fc — Improper Restriction of Rendered UI Layers or Frames in Keycloak</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3gg7-9q2x-79fc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3gg7-9q2x-79fc</guid>
    </item>
    <item>
      <title>gsd-2020-1728</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-1728</link>
      <description>gsd-2020-1728</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-1728</guid>
    </item>
    <item>
      <title>RHSA-2020:3495 — Red Hat Security Advisory: Red Hat Single Sign-On 7.4.2 security update on RHEL 6</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3495</link>
      <description>&lt;p&gt;keycloak: security headers missing on REST endpoints keycloak: DoS by sending multiple simultaneous requests with a Content-Length header value greater than actual byte count of request body&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak: security headers missing on REST endpoints keycloak: DoS by sending multiple simultaneous requests with a Content-Length header value greater than actual byte count of request body&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3495</guid>
    </item>
  </channel>
</rss>
