<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 12:56:41 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1094</link>
      <description>certfr-2022-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1094</guid>
    </item>
    <item>
      <title>cnvd-2022-87981</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-87981</link>
      <description>cnvd-2022-87981</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-87981</guid>
    </item>
    <item>
      <title>EUVD-2026-232017</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232017</link>
      <description>EUVD-2026-232017</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232017</guid>
    </item>
    <item>
      <title>fkie_cve-2022-44731</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-44731</link>
      <description>&lt;p&gt;A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions &amp;lt; V3.15 P038), SIMATIC WinCC OA V3.16 (All versions &amp;lt; V3.16 P035), SIMATIC WinCC OA V3.17 (All versions &amp;lt; V3.17 P024), SIMATIC WinCC OA V3.18 (All versions &amp;lt; V3.18 P014). The affected component allows to inject custom arguments to the Ultralight Client backend application under certain circumstances.&#13;
&#13;
This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker&amp;#39;s credentials or start a Ctrl script).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions &amp;lt; V3.15 P038), SIMATIC WinCC OA V3.16 (All versions &amp;lt; V3.16 P035), SIMATIC WinCC OA V3.17 (All versions &amp;lt; V3.17 P024), SIMATIC WinCC OA V3.18 (All versions &amp;lt; V3.18 P014). The affected component allows to inject custom arguments to the Ultralight Client backend application under certain circumstances.&#13;
&#13;
This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker&amp;#39;s credentials or start a Ctrl script).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-44731</guid>
    </item>
    <item>
      <title>GHSA-6qqj-p988-f82q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6qqj-p988-f82q</link>
      <description>&lt;p&gt;A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions), SIMATIC WinCC OA V3.16 (All versions &amp;lt; V3.16 P035), SIMATIC WinCC OA V3.17 (All versions &amp;lt; V3.17 P024), SIMATIC WinCC OA V3.18 (All versions &amp;lt; V3.18 P014). The affected component allows to inject custom arguments to the Ultralight Client backend application under certain circumstances. This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker&amp;#39;s credentials or start a Ctrl script).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions), SIMATIC WinCC OA V3.16 (All versions &amp;lt; V3.16 P035), SIMATIC WinCC OA V3.17 (All versions &amp;lt; V3.17 P024), SIMATIC WinCC OA V3.18 (All versions &amp;lt; V3.18 P014). The affected component allows to inject custom arguments to the Ultralight Client backend application under certain circumstances. This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker&amp;#39;s credentials or start a Ctrl script).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6qqj-p988-f82q</guid>
    </item>
    <item>
      <title>gsd-2022-44731</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-44731</link>
      <description>gsd-2022-44731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-44731</guid>
    </item>
    <item>
      <title>ICSA-22-349-06 — Siemens SIMATIC WinCC OA Ultralight Client</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-349-06</link>
      <description>&lt;p&gt;The affected component allows to inject custom arguments to the Ultralight Client backend application under certain circumstances.&#13;
&#13;
This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker&amp;#39;s credentials or start a Ctrl script).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected component allows to inject custom arguments to the Ultralight Client backend application under certain circumstances.&#13;
&#13;
This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker&amp;#39;s credentials or start a Ctrl script).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-349-06</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2295 — Siemens SIMATIC WinCC: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2295</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Siemens SIMATIC WinCC ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Siemens SIMATIC WinCC ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2295</guid>
    </item>
  </channel>
</rss>
