<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:17:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-01792</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01792</link>
      <description>bdu:2021-01792</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01792</guid>
    </item>
    <item>
      <title>certfr-2020-avi-726 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-726</link>
      <description>certfr-2020-avi-726</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-726</guid>
    </item>
    <item>
      <title>cnvd-2021-29457</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-29457</link>
      <description>cnvd-2021-29457</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-29457</guid>
    </item>
    <item>
      <title>EUVD-2026-38034</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-38034</link>
      <description>EUVD-2026-38034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-38034</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7572</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7572</link>
      <description>&lt;p&gt;A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial of service, server side request forgery due to improper configuration of the XML parser.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial of service, server side request forgery due to improper configuration of the XML parser.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7572</guid>
    </item>
    <item>
      <title>GHSA-vqmf-2v99-hhqq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vqmf-2v99-hhqq</link>
      <description>&lt;p&gt;A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial of service, server side request forgery due to improper configuration of the XML parser.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial of service, server side request forgery due to improper configuration of the XML parser.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vqmf-2v99-hhqq</guid>
    </item>
    <item>
      <title>gsd-2020-7572</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7572</link>
      <description>gsd-2020-7572</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7572</guid>
    </item>
    <item>
      <title>ICSA-21-063-02 — ICSA-21-063-02_Schneider Electric EcoStruxure Building Operation (EBO)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-063-02</link>
      <description>&lt;p&gt;An unrestricted upload of a file with dangerous type vulnerability could allow an authenticated remote user to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.CVE-2020-7569 has been assigned to this vulnerability. A CVSS v3 base score of 4.6 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L). An improper neutralization of an input during webpage generation vulnerability could allow an authenticated remote user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a stored cross-site scripting attack against other WebReport users.CVE-2020-7570 has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L). Multiple improper neutralizations of an input during webpage generation vulnerabilities could allow a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a reflected cross-site scripting attack against other WebReport users.CVE-2020-7571 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). An improper restriction of XML external entity reference vulnerability could allow an authenticated remote user to inject arbitrary XML code and obtain disclosure of confidential data, cause…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unrestricted upload of a file with dangerous type vulnerability could allow an authenticated remote user to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.CVE-2020-7569 has been assigned to this vulnerability. A CVSS v3 base score of 4.6 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L). An improper neutralization of an input during webpage generation vulnerability could allow an authenticated remote user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a stored cross-site scripting attack against other WebReport users.CVE-2020-7570 has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L). Multiple improper neutralizations of an input during webpage generation vulnerabilities could allow a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a reflected cross-site scripting attack against other WebReport users.CVE-2020-7571 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). An improper restriction of XML external entity reference vulnerability could allow an authenticated remote user to inject arbitrary XML code and obtain disclosure of confidential data, cause…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-063-02</guid>
    </item>
    <item>
      <title>SEVD-2020-315-04 — EcoStruxure Building Operation (EBO)</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2020-315-04</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure Building Operation&#13;
(EBO) product offerings. More information on the product line can be found at the following link:&#13;
https://www.se.com/ww/en/product-range-presentation/62111-ecostruxure%E2%84%A2-&#13;
building-operation/?parent-subcategory-id=1210&amp;amp;filter=business-2-building-automation-andcontrol#tabs-top&#13;
Failure to apply the mitigations/remediations provided below may risk various types of attacks &#13;
and cause various types of impact (see information below for each vulnerability).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure Building Operation&#13;
(EBO) product offerings. More information on the product line can be found at the following link:&#13;
https://www.se.com/ww/en/product-range-presentation/62111-ecostruxure%E2%84%A2-&#13;
building-operation/?parent-subcategory-id=1210&amp;amp;filter=business-2-building-automation-andcontrol#tabs-top&#13;
Failure to apply the mitigations/remediations provided below may risk various types of attacks &#13;
and cause various types of impact (see information below for each vulnerability).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2020-315-04</guid>
    </item>
  </channel>
</rss>
