<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:02:53 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-03222</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-03222</link>
      <description>bdu:2022-03222</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-03222</guid>
    </item>
    <item>
      <title>certfr-2022-avi-435 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-435</link>
      <description>certfr-2022-avi-435</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-435</guid>
    </item>
    <item>
      <title>cnvd-2022-37374</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-37374</link>
      <description>cnvd-2022-37374</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-37374</guid>
    </item>
    <item>
      <title>EUVD-2026-14014</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-14014</link>
      <description>EUVD-2026-14014</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-14014</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24045</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24045</link>
      <description>&lt;p&gt;A vulnerability has been identified in Desigo DXR2 (All versions &amp;lt; V01.21.142.5-22), Desigo PXC3 (All versions &amp;lt; V01.21.142.4-18), Desigo PXC4 (All versions &amp;lt; V02.20.142.10-10884), Desigo PXC5 (All versions &amp;lt; V02.20.142.10-10884). The application, after a successful login, sets the session cookie on the browser via client-side JavaScript code, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”). Any attempts to browse the application via unencrypted HTTP protocol would lead to the transmission of all his/her session cookies in plaintext through the network. An attacker could then be able to sniff the network and capture sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in Desigo DXR2 (All versions &amp;lt; V01.21.142.5-22), Desigo PXC3 (All versions &amp;lt; V01.21.142.4-18), Desigo PXC4 (All versions &amp;lt; V02.20.142.10-10884), Desigo PXC5 (All versions &amp;lt; V02.20.142.10-10884). The application, after a successful login, sets the session cookie on the browser via client-side JavaScript code, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”). Any attempts to browse the application via unencrypted HTTP protocol would lead to the transmission of all his/her session cookies in plaintext through the network. An attacker could then be able to sniff the network and capture sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24045</guid>
    </item>
    <item>
      <title>GHSA-gh3j-qg8j-hhvj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gh3j-qg8j-hhvj</link>
      <description>&lt;p&gt;A vulnerability has been identified in Desigo DXR2 (All versions &amp;lt; V01.21.142.5-22), Desigo PXC3 (All versions &amp;lt; V01.21.142.4-18), Desigo PXC4 (All versions &amp;lt; V02.20.142.10-10884), Desigo PXC5 (All versions &amp;lt; V02.20.142.10-10884). The application, after a successful login, sets the session cookie on the browser via client-side JavaScript code, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”). Any attempts to browse the application via unencrypted HTTP protocol would lead to the transmission of all his/her session cookies in plaintext through the network. An attacker could then be able to sniff the network and capture sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in Desigo DXR2 (All versions &amp;lt; V01.21.142.5-22), Desigo PXC3 (All versions &amp;lt; V01.21.142.4-18), Desigo PXC4 (All versions &amp;lt; V02.20.142.10-10884), Desigo PXC5 (All versions &amp;lt; V02.20.142.10-10884). The application, after a successful login, sets the session cookie on the browser via client-side JavaScript code, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”). Any attempts to browse the application via unencrypted HTTP protocol would lead to the transmission of all his/her session cookies in plaintext through the network. An attacker could then be able to sniff the network and capture sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gh3j-qg8j-hhvj</guid>
    </item>
    <item>
      <title>gsd-2022-24045</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24045</link>
      <description>gsd-2022-24045</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24045</guid>
    </item>
    <item>
      <title>ICSA-22-132-10 — Siemens Desigo PXC and DXR Devices</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-132-10</link>
      <description>&lt;p&gt;The addCell JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document as it is possible to inject arbitrary content (e.g., XML tags) into the generated file. An attacker with restricted privileges could corrupt the content used to generate XLS reports to leverage the application to deliver malicious files against higher-privileged users and obtain remote code execution (RCE) against the administrator &amp;#39;s workstation.CVE-2022-24039 has been assigned to this vulnerability. A CVSS v3 base score of 9.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). The web application fails to enforce an upper bound to the cost factor of the PBKDF2 derived key during the creation or update of an account. An attacker with the user profile access privilege could cause a denial-of-service condition through CPU consumption by setting a PBKDF2 derived key with a high-cost effort, followed by a login attempt to the modified account.CVE-2022-24040 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). The web application stores the PBKDF2 derived key of user &amp;#39;s passwords with a low iteration count. An attacker with user profile access privilege can retrieve the stored password hashes of other accounts and then successfully perform an offline cracking attack and recover the plainte…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The addCell JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document as it is possible to inject arbitrary content (e.g., XML tags) into the generated file. An attacker with restricted privileges could corrupt the content used to generate XLS reports to leverage the application to deliver malicious files against higher-privileged users and obtain remote code execution (RCE) against the administrator &amp;#39;s workstation.CVE-2022-24039 has been assigned to this vulnerability. A CVSS v3 base score of 9.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). The web application fails to enforce an upper bound to the cost factor of the PBKDF2 derived key during the creation or update of an account. An attacker with the user profile access privilege could cause a denial-of-service condition through CPU consumption by setting a PBKDF2 derived key with a high-cost effort, followed by a login attempt to the modified account.CVE-2022-24040 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). The web application stores the PBKDF2 derived key of user &amp;#39;s passwords with a low iteration count. An attacker with user profile access privilege can retrieve the stored password hashes of other accounts and then successfully perform an offline cracking attack and recover the plainte…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-132-10</guid>
    </item>
  </channel>
</rss>
