<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:11:15 +0000</lastBuildDate>
    <item>
      <title>cnvd-2021-40050</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-40050</link>
      <description>cnvd-2021-40050</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-40050</guid>
    </item>
    <item>
      <title>EUVD-2026-178858</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-178858</link>
      <description>EUVD-2026-178858</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-178858</guid>
    </item>
    <item>
      <title>fkie_cve-2021-27657</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-27657</link>
      <description>&lt;p&gt;Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-27657</guid>
    </item>
    <item>
      <title>GHSA-g3gv-gq3r-m3m6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g3gv-gq3r-m3m6</link>
      <description>&lt;p&gt;Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g3gv-gq3r-m3m6</guid>
    </item>
    <item>
      <title>gsd-2021-27657</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-27657</link>
      <description>gsd-2021-27657</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-27657</guid>
    </item>
    <item>
      <title>ICSA-21-159-01 — Johnson Controls Metasys</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-159-01</link>
      <description>&lt;p&gt;Metasys servers, engines, and tools do not properly assign, modify, track, or check privileges for an actor, thus creating an unintended sphere of control for said actor. CVE-2021-27657 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Metasys servers, engines, and tools do not properly assign, modify, track, or check privileges for an actor, thus creating an unintended sphere of control for said actor. CVE-2021-27657 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-159-01</guid>
    </item>
  </channel>
</rss>
