<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:45:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-221467</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-221467</link>
      <description>EUVD-2026-221467</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-221467</guid>
    </item>
    <item>
      <title>fkie_cve-2022-45139</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-45139</link>
      <description>&lt;p&gt;A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-45139</guid>
    </item>
    <item>
      <title>GHSA-p586-5mqw-6f9x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p586-5mqw-6f9x</link>
      <description>&lt;p&gt;A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p586-5mqw-6f9x</guid>
    </item>
    <item>
      <title>gsd-2022-45139</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-45139</link>
      <description>gsd-2022-45139</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-45139</guid>
    </item>
    <item>
      <title>VDE-2022-060 — WAGO: Multiple vulnerabilities in web-based management of multiple products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-060</link>
      <description>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.
The configuration backend can in some cases be used without authentication and to write data with root privileges. Additionally, the web-based management suffers a CORS misconfiguration and allows reflected XSS (Cross-Site Scripting) attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates.
The configuration backend can in some cases be used without authentication and to write data with root privileges. Additionally, the web-based management suffers a CORS misconfiguration and allows reflected XSS (Cross-Site Scripting) attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-060</guid>
    </item>
    <item>
      <title>VDE-2024-054 — Endress+Hauser: Netilion Network Insights is affected by multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-054</link>
      <description>&lt;p&gt;Several vulnerabilities have been identified in the web-based management of WAGO devices utilized in
Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been
integrated into the solutions by Endress+Hauser. Additionally, a guideline on secure operation of these
solutions has been made available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several vulnerabilities have been identified in the web-based management of WAGO devices utilized in
Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been
integrated into the solutions by Endress+Hauser. Additionally, a guideline on secure operation of these
solutions has been made available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-054</guid>
    </item>
  </channel>
</rss>
