<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:45:31 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-08419</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08419</link>
      <description>bdu:2023-08419</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08419</guid>
    </item>
    <item>
      <title>EUVD-2026-210915</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-210915</link>
      <description>EUVD-2026-210915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-210915</guid>
    </item>
    <item>
      <title>fkie_cve-2023-28648</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28648</link>
      <description>&lt;p&gt;Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user&amp;#39;s browser session in context of an affected site.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user&amp;#39;s browser session in context of an affected site.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-28648</guid>
    </item>
    <item>
      <title>GHSA-4mpv-9j83-cm3q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4mpv-9j83-cm3q</link>
      <description>&lt;p&gt;Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user&amp;#39;s browser session in context of an affected site.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user&amp;#39;s browser session in context of an affected site.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4mpv-9j83-cm3q</guid>
    </item>
    <item>
      <title>gsd-2023-28648</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-28648</link>
      <description>gsd-2023-28648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-28648</guid>
    </item>
    <item>
      <title>ICSA-23-082-06 — ProPump and Controls Osprey Pump Controller (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-082-06</link>
      <description>&lt;p&gt;Osprey Pump Controller versions prior to release 20230518 are vulnerable to a predictable weak session token generation algorithm and could aid in authentication and authorization bypass. This could allow a cyber threat actor to hijack a session by predicting the session ID and gain unauthorized access to the product. Osprey Pump Controller versions prior to release 20230518 are vulnerable to an unauthenticated file disclosure. Cyber threat actors could use a GET parameter to force the affected device to disclose arbitrary files and sensitive system information. Osprey Pump Controller versions prior to release 20230518 have a hidden administrative account with a hardcoded password that allows full access to the web management interface configuration. The account is not visible in the Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation of the device. Osprey Pump Controller versions prior to release 20230518 are vulnerable to an unauthenticated OS command injection vulnerability. Threat actors could exploit this vulnerability to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script. Osprey Pump Controller versions prior to release 20230518 are vulnerable an unauthenticated OS command injection vulnerability. Threat actors could exploit this vulnerability to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Osprey Pump Controller versions prior to release 20230518 are vulnerable to a predictable weak session token generation algorithm and could aid in authentication and authorization bypass. This could allow a cyber threat actor to hijack a session by predicting the session ID and gain unauthorized access to the product. Osprey Pump Controller versions prior to release 20230518 are vulnerable to an unauthenticated file disclosure. Cyber threat actors could use a GET parameter to force the affected device to disclose arbitrary files and sensitive system information. Osprey Pump Controller versions prior to release 20230518 have a hidden administrative account with a hardcoded password that allows full access to the web management interface configuration. The account is not visible in the Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation of the device. Osprey Pump Controller versions prior to release 20230518 are vulnerable to an unauthenticated OS command injection vulnerability. Threat actors could exploit this vulnerability to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script. Osprey Pump Controller versions prior to release 20230518 are vulnerable an unauthenticated OS command injection vulnerability. Threat actors could exploit this vulnerability to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-082-06</guid>
    </item>
  </channel>
</rss>
