<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:58:36 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03533</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03533</link>
      <description>bdu:2023-03533</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03533</guid>
    </item>
    <item>
      <title>EUVD-2026-221920</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-221920</link>
      <description>EUVD-2026-221920</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-221920</guid>
    </item>
    <item>
      <title>fkie_cve-2022-1607</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1607</link>
      <description>&lt;p&gt;Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-1607</guid>
    </item>
    <item>
      <title>GHSA-f5m2-fr27-39rx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f5m2-fr27-39rx</link>
      <description>&lt;p&gt;Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f5m2-fr27-39rx</guid>
    </item>
    <item>
      <title>gsd-2022-1607</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-1607</link>
      <description>gsd-2022-1607</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-1607</guid>
    </item>
    <item>
      <title>ICSA-23-082-05 — ABB Pulsar Plus Controller</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-082-05</link>
      <description>&lt;p&gt;There are several fields in the web pages where a user can enter arbitrary text such as a description of an alarm or a rectifier. These represent a cross site scripting vulnerability where javascript code can be entered as the description with the potential of causing system interactions unknown to the user. These issues were remediated by adding a check of every field update to reject suspicious entries. CVE-2022-1607 has been assigned to this vulnerability. A CVSS v3 base score of 4.6 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N). Every interaction with the web server requires a Session ID that is assigned to the session after a successful login. The reported vulnerability is that the Session IDs were too short (16 bits), too predictable (IDs simply incremented), and were plainly visible in the URLs of the web pages. These issues were remediated by rewriting the web server to follow recommended best practices.  CVE-2022-26080 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There are several fields in the web pages where a user can enter arbitrary text such as a description of an alarm or a rectifier. These represent a cross site scripting vulnerability where javascript code can be entered as the description with the potential of causing system interactions unknown to the user. These issues were remediated by adding a check of every field update to reject suspicious entries. CVE-2022-1607 has been assigned to this vulnerability. A CVSS v3 base score of 4.6 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N). Every interaction with the web server requires a Session ID that is assigned to the session after a successful login. The reported vulnerability is that the Session IDs were too short (16 bits), too predictable (IDs simply incremented), and were plainly visible in the URLs of the web pages. These issues were remediated by rewriting the web server to follow recommended best practices.  CVE-2022-26080 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-082-05</guid>
    </item>
  </channel>
</rss>
