<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:15:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-05180</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-05180</link>
      <description>bdu:2020-05180</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-05180</guid>
    </item>
    <item>
      <title>cnvd-2020-29873</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-29873</link>
      <description>cnvd-2020-29873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-29873</guid>
    </item>
    <item>
      <title>EUVD-2026-35740</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35740</link>
      <description>EUVD-2026-35740</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35740</guid>
    </item>
    <item>
      <title>fkie_cve-2020-1954</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1954</link>
      <description>&lt;p&gt;Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-1954</guid>
    </item>
    <item>
      <title>GHSA-ffm7-7r8g-77xm — Apache CXF JMX Integration is vulnerable to a MITM attack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ffm7-7r8g-77xm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-rt-management&lt;/p&gt;
&lt;p&gt;Apache CXF has the ability to integrate with JMX by registering an `InstrumentationManager` extension with the CXF bus. If the `createMBServerConnectorFactory` property of the default `InstrumentationManagerImpl` is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-rt-management&lt;/p&gt;
&lt;p&gt;Apache CXF has the ability to integrate with JMX by registering an `InstrumentationManager` extension with the CXF bus. If the `createMBServerConnectorFactory` property of the default `InstrumentationManagerImpl` is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ffm7-7r8g-77xm</guid>
    </item>
    <item>
      <title>gsd-2020-1954</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-1954</link>
      <description>gsd-2020-1954</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-1954</guid>
    </item>
    <item>
      <title>RHSA-2020:3585 — Red Hat Security Advisory: EAP Continuous Delivery Technical Preview Release 20 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3585</link>
      <description>&lt;p&gt;mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter jackson-mapper-asl: XML external entity similar to CVE-2016-3720 hibernate: SQL injection issue in Hibernate ORM Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain cxf: JMX integration is vulnerable to a MITM attack Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution dom4j: XML External Entity vulnerability in default SAX parser undertow: Memory exhaustion issue in HttpReadListener via &amp;#34;Expect: 100-continue&amp;#34; header wildfly-elytron: session fixation when using FORM authentication undertow: invalid HTTP request with large chunk size wildfly: unsafe deserialization in Wildfly Enterprise Java Beans netty: compression/decompression codecs don&amp;#39;t enforce limits on buffer allocation sizes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter jackson-mapper-asl: XML external entity similar to CVE-2016-3720 hibernate: SQL injection issue in Hibernate ORM Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain cxf: JMX integration is vulnerable to a MITM attack Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution dom4j: XML External Entity vulnerability in default SAX parser undertow: Memory exhaustion issue in HttpReadListener via &amp;#34;Expect: 100-continue&amp;#34; header wildfly-elytron: session fixation when using FORM authentication undertow: invalid HTTP request with large chunk size wildfly: unsafe deserialization in Wildfly Enterprise Java Beans netty: compression/decompression codecs don&amp;#39;t enforce limits on buffer allocation sizes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3585</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0180 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</guid>
    </item>
  </channel>
</rss>
