<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:08:00 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-03746</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-03746</link>
      <description>bdu:2022-03746</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-03746</guid>
    </item>
    <item>
      <title>BIT-tomcat-2022-34305 — XSS in examples web application</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2022-34305</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;In Apache Tomcat 10.1.0 to 10.1.0, 10.0.0 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;In Apache Tomcat 10.1.0 to 10.1.0, 10.0.0 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2022-34305</guid>
    </item>
    <item>
      <title>certfr-2022-avi-579 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer une injection de code in…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-579</link>
      <description>certfr-2022-avi-579</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-579</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AJ47488 — When using the RemoteIpFilter with requests received from a    reverse proxy via HTTP that include the X-Forwarded-Prot…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tomcat10&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tomcat10 package. When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tomcat10&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tomcat10 package. When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aj47488</guid>
    </item>
    <item>
      <title>EUVD-2026-17835</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-17835</link>
      <description>EUVD-2026-17835</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-17835</guid>
    </item>
    <item>
      <title>fkie_cve-2022-34305</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-34305</link>
      <description>&lt;p&gt;In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-34305</guid>
    </item>
    <item>
      <title>GHSA-6j88-6whg-x687 — Cross-site Scripting in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6j88-6whg-x687</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6j88-6whg-x687</guid>
    </item>
    <item>
      <title>gsd-2022-34305</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-34305</link>
      <description>gsd-2022-34305</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-34305</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-34305</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-34305</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-34305</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0449 — Apache Tomcat: Schwachstelle ermöglicht Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0449</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0449</guid>
    </item>
  </channel>
</rss>
