<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:35:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-05231</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05231</link>
      <description>bdu:2022-05231</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05231</guid>
    </item>
    <item>
      <title>certfr-2021-avi-770 — De multiples vulnérabilités ont été découvertes dans les produits SAP.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-770</link>
      <description>certfr-2021-avi-770</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-770</guid>
    </item>
    <item>
      <title>cnvd-2021-03544</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-03544</link>
      <description>cnvd-2021-03544</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-03544</guid>
    </item>
    <item>
      <title>EUVD-2026-215948</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215948</link>
      <description>EUVD-2026-215948</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215948</guid>
    </item>
    <item>
      <title>fkie_cve-2021-23926</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-23926</link>
      <description>&lt;p&gt;The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-23926</guid>
    </item>
    <item>
      <title>GHSA-mw3r-pfmg-xp92 — Improper Restriction of Recursive Entity References in Apache XMLBeans</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mw3r-pfmg-xp92</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.xmlbeans:xmlbeans&lt;/p&gt;
&lt;p&gt;The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.xmlbeans:xmlbeans&lt;/p&gt;
&lt;p&gt;The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mw3r-pfmg-xp92</guid>
    </item>
    <item>
      <title>gsd-2021-23926</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-23926</link>
      <description>gsd-2021-23926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-23926</guid>
    </item>
    <item>
      <title>NCSC-2026-0028 — Kwetsbaarheden verholpen in Oracle Analytics</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0028</link>
      <description>NCSC-2026-0028</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0028</guid>
    </item>
    <item>
      <title>OESA-2021-1077 — xmlbeans security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1077</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xmlbeans&lt;/p&gt;
&lt;p&gt;XMLBeans is a tool that allows you to access the full power of XML in a Java friendly way. It is an XML-Java binding tool. The idea is that you can take advantage the richness and features of XML and XML Schema and have these features mapped as naturally as possible to the equivalent Java language and typing constructs. XMLBeans uses XML Schema to compile Java interfaces and classes that you can then use to access and modify XML instance data. Using XMLBeans is similar to using any other Java interface/class, you will see things like getFoo or setFoo just as you would expect when working with Java. While a major use of XMLBeans is to access your XML instance data with strongly typed Java classes there are also API&amp;#39;s that allow you access to the full XML infoset (XMLBeans keeps full XML Infoset fidelity) as well as to allow you to reflect into the XML schema itself through an XML Schema Object model.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.(CVE-2021-23926)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: xmlbeans&lt;/p&gt;
&lt;p&gt;XMLBeans is a tool that allows you to access the full power of XML in a Java friendly way. It is an XML-Java binding tool. The idea is that you can take advantage the richness and features of XML and XML Schema and have these features mapped as naturally as possible to the equivalent Java language and typing constructs. XMLBeans uses XML Schema to compile Java interfaces and classes that you can then use to access and modify XML instance data. Using XMLBeans is similar to using any other Java interface/class, you will see things like getFoo or setFoo just as you would expect when working with Java. While a major use of XMLBeans is to access your XML instance data with strongly typed Java classes there are also API&amp;#39;s that allow you access to the full XML infoset (XMLBeans keeps full XML Infoset fidelity) as well as to allow you to reflect into the XML schema itself through an XML Schema Object model.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.(CVE-2021-23926)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1077</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12455-1 — xmlbeans-2.6.0-12.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12455-1</link>
      <description>&lt;p&gt;xmlbeans-2.6.0-12.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmlbeans-2.6.0-12.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12455-1</guid>
    </item>
    <item>
      <title>RHSA-2021:5134 — Red Hat Security Advisory: Red Hat Fuse 7.10.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:5134</link>
      <description>&lt;p&gt;nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem mysql-connector-java: allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors which could result in unauthorized update, insert or delete mysql-connector-java: allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors which could result in unauthorized update, insert or delete log4j: improper validation of certificate with host mismatch in SMTP appender batik: SSRF due to improper input validation by the NodePickerPanel xmlgraphics-commons: SSRF due to improper input validation by the XMPParser tomcat: Apache Tomcat HTTP/2 Request mix-up libthrift: potential DoS when processing untrusted payloads bouncycastle: Timing issue within the EC math library groovy: OS temporary directory leads to information disclosure tomcat: HTTP/2 request header mix-up XStream: remote code execution due to insecure XML deserialization when relying on blocklists XStream: arbitrary file deletion on the local host when unmarshalling jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS undertow: special character in query results in server errors jackson-dataformat-cbor: Unchecked allocation…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties poi: a specially crafted Microsoft Excel document allows attacker to read files from the local filesystem mysql-connector-java: allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors which could result in unauthorized update, insert or delete mysql-connector-java: allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors which could result in unauthorized update, insert or delete log4j: improper validation of certificate with host mismatch in SMTP appender batik: SSRF due to improper input validation by the NodePickerPanel xmlgraphics-commons: SSRF due to improper input validation by the XMPParser tomcat: Apache Tomcat HTTP/2 Request mix-up libthrift: potential DoS when processing untrusted payloads bouncycastle: Timing issue within the EC math library groovy: OS temporary directory leads to information disclosure tomcat: HTTP/2 request header mix-up XStream: remote code execution due to insecure XML deserialization when relying on blocklists XStream: arbitrary file deletion on the local host when unmarshalling jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of &amp;#34;quality&amp;#34; parameters may lead to DoS undertow: special character in query results in server errors jackson-dataformat-cbor: Unchecked allocation…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:5134</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3876-1 — Security update for xmlbeans</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3876-1</link>
      <description>&lt;p&gt;Security update for xmlbeans&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for xmlbeans&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3876-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-23926</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23926</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: xmlbeans, Ubuntu:18.04:LTS: xmlbeans&lt;/p&gt;
&lt;p&gt;The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: xmlbeans, Ubuntu:18.04:LTS: xmlbeans&lt;/p&gt;
&lt;p&gt;The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23926</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1807 — Oracle Fusion Middleware: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1807</guid>
    </item>
  </channel>
</rss>
