<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:51:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-12369</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-12369</link>
      <description>EUVD-2026-12369</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-12369</guid>
    </item>
    <item>
      <title>fkie_cve-2022-2458</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2458</link>
      <description>&lt;p&gt;XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application&amp;#39;s processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, XML external entity injection lead to External Service interaction &amp;amp; Internal file read in Business Central and also Kie-Server APIs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application&amp;#39;s processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, XML external entity injection lead to External Service interaction &amp;amp; Internal file read in Business Central and also Kie-Server APIs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-2458</guid>
    </item>
    <item>
      <title>GHSA-hfj4-xq5f-7mc7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hfj4-xq5f-7mc7</link>
      <description>&lt;p&gt;XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application&amp;#39;s processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, XML external entity injection lead to External Service interaction &amp;amp; Internal file read in Business Central and also Kie-Server APIs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application&amp;#39;s processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, XML external entity injection lead to External Service interaction &amp;amp; Internal file read in Business Central and also Kie-Server APIs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hfj4-xq5f-7mc7</guid>
    </item>
    <item>
      <title>gsd-2022-2458</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-2458</link>
      <description>gsd-2022-2458</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-2458</guid>
    </item>
    <item>
      <title>RHSA-2022:6813 — Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6813</link>
      <description>&lt;p&gt;chart.js: prototype pollution jackson-databind: denial of service via a large depth of nested objects immer: type confusion vulnerability can lead to a bypass of CVE-2020-28477 minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor parse-url: Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor drools: unsafe data deserialization in StreamUtils eventsource: Exposure of Sensitive Information Business-central: Possible XML External Entity Injection attack mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes xerces-j2: infinite loop when handling specially crafted XML document payloads artemis-commons: Apache ActiveMQ Artemis DoS node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery Moment.js: Path traversal  in moment.locale postgresql-jdbc: Arbitrary File Write Vulnerability moment: inefficient parsing algorithm resulting in DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;chart.js: prototype pollution jackson-databind: denial of service via a large depth of nested objects immer: type confusion vulnerability can lead to a bypass of CVE-2020-28477 minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor parse-url: Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor drools: unsafe data deserialization in StreamUtils eventsource: Exposure of Sensitive Information Business-central: Possible XML External Entity Injection attack mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes xerces-j2: infinite loop when handling specially crafted XML document payloads artemis-commons: Apache ActiveMQ Artemis DoS node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery Moment.js: Path traversal  in moment.locale postgresql-jdbc: Arbitrary File Write Vulnerability moment: inefficient parsing algorithm resulting in DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6813</guid>
    </item>
  </channel>
</rss>
