<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:26:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-07907</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07907</link>
      <description>bdu:2023-07907</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07907</guid>
    </item>
    <item>
      <title>certfr-2022-avi-366 — De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft.
Certaines d'entre elles permettent à un attaqua…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-366</link>
      <description>certfr-2022-avi-366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-366</guid>
    </item>
    <item>
      <title>EUVD-2026-31313</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-31313</link>
      <description>EUVD-2026-31313</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-31313</guid>
    </item>
    <item>
      <title>fkie_cve-2021-40690</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-40690</link>
      <description>&lt;p&gt;All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the &amp;#34;secureValidation&amp;#34; property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the &amp;#34;secureValidation&amp;#34; property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-40690</guid>
    </item>
    <item>
      <title>GHSA-j8wc-gxx9-82hx — Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j8wc-gxx9-82hx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.santuario:xmlsec&lt;/p&gt;
&lt;p&gt;All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the &amp;#34;secureValidation&amp;#34; property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.santuario:xmlsec&lt;/p&gt;
&lt;p&gt;All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the &amp;#34;secureValidation&amp;#34; property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j8wc-gxx9-82hx</guid>
    </item>
    <item>
      <title>gsd-2021-40690</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-40690</link>
      <description>gsd-2021-40690</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-40690</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11693-1 — xml-security-2.1.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11693-1</link>
      <description>&lt;p&gt;xml-security-2.1.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xml-security-2.1.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11693-1</guid>
    </item>
    <item>
      <title>RHSA-2021:4679 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4679</link>
      <description>&lt;p&gt;undertow: potential security issue in flow control over HTTP/2 may lead to DOS wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users resteasy: Error message exposes endpoint class information mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck xml-security: XPath Transform abuse allows for information disclosure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undertow: potential security issue in flow control over HTTP/2 may lead to DOS wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users resteasy: Error message exposes endpoint class information mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck xml-security: XPath Transform abuse allows for information disclosure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4679</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-40690</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-40690</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libxml-security-java, Ubuntu:18.04:LTS: libxml-security-java, Ubuntu:20.04:LTS: libxml-security-java&lt;/p&gt;
&lt;p&gt;All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the &amp;#34;secureValidation&amp;#34; property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libxml-security-java, Ubuntu:18.04:LTS: libxml-security-java, Ubuntu:20.04:LTS: libxml-security-java&lt;/p&gt;
&lt;p&gt;All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the &amp;#34;secureValidation&amp;#34; property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-40690</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</guid>
    </item>
  </channel>
</rss>
