<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:27:06 +0000</lastBuildDate>
    <item>
      <title>cnvd-2021-31670</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-31670</link>
      <description>cnvd-2021-31670</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-31670</guid>
    </item>
    <item>
      <title>EUVD-2026-181835</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-181835</link>
      <description>EUVD-2026-181835</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-181835</guid>
    </item>
    <item>
      <title>fkie_cve-2021-23276</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-23276</link>
      <description>&lt;p&gt;Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-23276</guid>
    </item>
    <item>
      <title>GHSA-c2vv-8742-cw24</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c2vv-8742-cw24</link>
      <description>&lt;p&gt;Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c2vv-8742-cw24</guid>
    </item>
    <item>
      <title>gsd-2021-23276</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-23276</link>
      <description>gsd-2021-23276</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-23276</guid>
    </item>
    <item>
      <title>ICSA-21-110-06 — Eaton Intelligent Power Manager</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-110-06</link>
      <description>&lt;p&gt;Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit this vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.CVE-2021-23276 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to an unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in the loadUserFile function under scripts/libs/utils.js. Successful exploitation can allow attackers to control the input to the function and execute attacker-controlled commands.CVE-2021-23277 has been assigned to this vulnerability. A CVSS v3 base score of 8.3 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to an authenticated arbitrary file delete vulnerability induced due to improper input validation at server/maps_srv.js with the removeBackground function and server/node_upgrade_srv.js with the removeFirmware function. An attacker can send specially crafted packets to delete the files on the system where IPM software is installed.CVE-2021-23278 has been assigned to this vulnerability. A CVSS v3 base score of 8.7 h…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit this vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.CVE-2021-23276 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to an unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in the loadUserFile function under scripts/libs/utils.js. Successful exploitation can allow attackers to control the input to the function and execute attacker-controlled commands.CVE-2021-23277 has been assigned to this vulnerability. A CVSS v3 base score of 8.3 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to an authenticated arbitrary file delete vulnerability induced due to improper input validation at server/maps_srv.js with the removeBackground function and server/node_upgrade_srv.js with the removeFirmware function. An attacker can send specially crafted packets to delete the files on the system where IPM software is installed.CVE-2021-23278 has been assigned to this vulnerability. A CVSS v3 base score of 8.7 h…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-110-06</guid>
    </item>
  </channel>
</rss>
