<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:44:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-198571</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-198571</link>
      <description>EUVD-2026-198571</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-198571</guid>
    </item>
    <item>
      <title>fkie_cve-2023-38286</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-38286</link>
      <description>&lt;p&gt;Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-38286</guid>
    </item>
    <item>
      <title>GHSA-7gj7-224w-vpr3 — Spring-boot-admin sandbox bypass via crafted HTML</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7gj7-224w-vpr3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: de.codecentric:spring-boot-admin-server&lt;/p&gt;
&lt;p&gt;Thymeleaf through 3.1.1.RELEASE as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 allows for a sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.&lt;/p&gt;
&lt;p&gt;Spring Boot Admin 3.1.2 and 2.7.16 contain mitigations for the issue. This bypass is achived via a library called Thymeleaf which has added counter measures for this sort of bypass in version `3.1.2.RELEASE` which has explicity forbidden static access to `org.springframework.util` in expressions. Thymeleaf itself should not be considered vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: de.codecentric:spring-boot-admin-server&lt;/p&gt;
&lt;p&gt;Thymeleaf through 3.1.1.RELEASE as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 allows for a sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.&lt;/p&gt;
&lt;p&gt;Spring Boot Admin 3.1.2 and 2.7.16 contain mitigations for the issue. This bypass is achived via a library called Thymeleaf which has added counter measures for this sort of bypass in version `3.1.2.RELEASE` which has explicity forbidden static access to `org.springframework.util` in expressions. Thymeleaf itself should not be considered vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7gj7-224w-vpr3</guid>
    </item>
    <item>
      <title>gsd-2023-38286</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-38286</link>
      <description>gsd-2023-38286</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-38286</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3377 — Dell PowerProtect Data Domain: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3377</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Dell PowerProtect Data Domain ausnutzen, um seine Privilegien zu erhöhen, Informationen offenzulegen und um nicht näher beschriebene Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Dell PowerProtect Data Domain ausnutzen, um seine Privilegien zu erhöhen, Informationen offenzulegen und um nicht näher beschriebene Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3377</guid>
    </item>
  </channel>
</rss>
