<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:16:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-06568</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06568</link>
      <description>bdu:2022-06568</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06568</guid>
    </item>
    <item>
      <title>EUVD-2026-188438</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-188438</link>
      <description>EUVD-2026-188438</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-188438</guid>
    </item>
    <item>
      <title>fkie_cve-2022-1415</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1415</link>
      <description>&lt;p&gt;A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-1415</guid>
    </item>
    <item>
      <title>GHSA-m5q8-58wh-xxq4 — Drools Core Deserialization of Untrusted Data vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m5q8-58wh-xxq4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.drools:drools-core&lt;/p&gt;
&lt;p&gt;A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.drools:drools-core&lt;/p&gt;
&lt;p&gt;A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m5q8-58wh-xxq4</guid>
    </item>
    <item>
      <title>gsd-2022-1415</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-1415</link>
      <description>gsd-2022-1415</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-1415</guid>
    </item>
    <item>
      <title>RHSA-2022:6813 — Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6813</link>
      <description>&lt;p&gt;chart.js: prototype pollution jackson-databind: denial of service via a large depth of nested objects immer: type confusion vulnerability can lead to a bypass of CVE-2020-28477 minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor parse-url: Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor drools: unsafe data deserialization in StreamUtils eventsource: Exposure of Sensitive Information Business-central: Possible XML External Entity Injection attack mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes xerces-j2: infinite loop when handling specially crafted XML document payloads artemis-commons: Apache ActiveMQ Artemis DoS node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery Moment.js: Path traversal  in moment.locale postgresql-jdbc: Arbitrary File Write Vulnerability moment: inefficient parsing algorithm resulting in DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;chart.js: prototype pollution jackson-databind: denial of service via a large depth of nested objects immer: type confusion vulnerability can lead to a bypass of CVE-2020-28477 minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor parse-url: Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor drools: unsafe data deserialization in StreamUtils eventsource: Exposure of Sensitive Information Business-central: Possible XML External Entity Injection attack mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes xerces-j2: infinite loop when handling specially crafted XML document payloads artemis-commons: Apache ActiveMQ Artemis DoS node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery Moment.js: Path traversal  in moment.locale postgresql-jdbc: Arbitrary File Write Vulnerability moment: inefficient parsing algorithm resulting in DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6813</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:0345-1 — Security update for SUSE Manager Server 4.3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:0345-1</link>
      <description>&lt;p&gt;Security update for SUSE Manager Server 4.3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Server 4.3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:0345-1</guid>
    </item>
  </channel>
</rss>
