<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:30:12 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-08569</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08569</link>
      <description>bdu:2023-08569</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08569</guid>
    </item>
    <item>
      <title>EUVD-2026-270646</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270646</link>
      <description>EUVD-2026-270646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270646</guid>
    </item>
    <item>
      <title>fkie_cve-2023-40461</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-40461</link>
      <description>&lt;p&gt;The ACEManager
component of ALEOS 4.16 and earlier allows an&lt;/p&gt;
&lt;p&gt;authenticated user
with Administrator privileges to access a file&lt;/p&gt;
&lt;p&gt;upload field which
does not fully validate the file name, creating a&lt;/p&gt;
&lt;p&gt;Stored Cross-Site
Scripting condition.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ACEManager
component of ALEOS 4.16 and earlier allows an&lt;/p&gt;
&lt;p&gt;authenticated user
with Administrator privileges to access a file&lt;/p&gt;
&lt;p&gt;upload field which
does not fully validate the file name, creating a&lt;/p&gt;
&lt;p&gt;Stored Cross-Site
Scripting condition.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-40461</guid>
    </item>
    <item>
      <title>GHSA-78cf-35f9-pxqf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-78cf-35f9-pxqf</link>
      <description>&lt;p&gt;The ACEManager
component of ALEOS 4.16 and earlier allows an&lt;/p&gt;
&lt;p&gt;authenticated user
with Administrator privileges to access a file&lt;/p&gt;
&lt;p&gt;upload field which
does not fully validate the file name, creating a&lt;/p&gt;
&lt;p&gt;Stored Cross-Site
Scripting condition.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ACEManager
component of ALEOS 4.16 and earlier allows an&lt;/p&gt;
&lt;p&gt;authenticated user
with Administrator privileges to access a file&lt;/p&gt;
&lt;p&gt;upload field which
does not fully validate the file name, creating a&lt;/p&gt;
&lt;p&gt;Stored Cross-Site
Scripting condition.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-78cf-35f9-pxqf</guid>
    </item>
    <item>
      <title>gsd-2023-40461</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-40461</link>
      <description>gsd-2023-40461</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-40461</guid>
    </item>
    <item>
      <title>ICSA-23-341-06 — Sierra Wireless AirLink with ALEOS firmware</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-341-06</link>
      <description>&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device. The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable. The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted. The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition. The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable. When…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device. The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable. The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted. The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition. The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable. When…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-341-06</guid>
    </item>
  </channel>
</rss>
