<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:06:27 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-1057 — De multiples vulnérabilités ont été découvertes dans les produits
Nextcloud. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1057</link>
      <description>certfr-2022-avi-1057</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1057</guid>
    </item>
    <item>
      <title>EUVD-2026-233391</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-233391</link>
      <description>EUVD-2026-233391</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-233391</guid>
    </item>
    <item>
      <title>fkie_cve-2022-39338</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39338</link>
      <description>&lt;p&gt;user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the restrictive CSP that is applied on this endpoint. Additionally this vulnerability has only been shown to be exploitable in the Safari web browser. This issue has been addressed in version 1.2.1. Users are advised to upgrade. Users unable to upgrade should urge their users to avoid using the Safari web browser.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the restrictive CSP that is applied on this endpoint. Additionally this vulnerability has only been shown to be exploitable in the Safari web browser. This issue has been addressed in version 1.2.1. Users are advised to upgrade. Users unable to upgrade should urge their users to avoid using the Safari web browser.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-39338</guid>
    </item>
    <item>
      <title>gsd-2022-39338</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-39338</link>
      <description>gsd-2022-39338</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-39338</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2183 — Nextcloud: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2183</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Nextcloud ausnutzen, um einen Denial of Service Angriff durchzuführen, Informationen offenzulegen, einen Cross-Site-Scripting-Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Nextcloud ausnutzen, um einen Denial of Service Angriff durchzuführen, Informationen offenzulegen, einen Cross-Site-Scripting-Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2183</guid>
    </item>
  </channel>
</rss>
