<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:21:53 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0337 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337</link>
      <description>certfr-2025-avi-0337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</guid>
    </item>
    <item>
      <title>EUVD-2026-208887</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-208887</link>
      <description>EUVD-2026-208887</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-208887</guid>
    </item>
    <item>
      <title>fkie_cve-2024-12801</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-12801</link>
      <description>&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to 
forge requests by compromising logback configuration files in XML.&lt;/p&gt;
&lt;p&gt;The attacks involves the modification of DOCTYPE declaration in  XML configuration files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to 
forge requests by compromising logback configuration files in XML.&lt;/p&gt;
&lt;p&gt;The attacks involves the modification of DOCTYPE declaration in  XML configuration files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-12801</guid>
    </item>
    <item>
      <title>GHSA-6v67-2wr5-gvf4 — QOS.CH logback-core Server-Side Request Forgery vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6v67-2wr5-gvf4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ch.qos.logback:logback-core&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML.
 
The attacks involves the modification of DOCTYPE declaration in  XML configuration files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ch.qos.logback:logback-core&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML.
 
The attacks involves the modification of DOCTYPE declaration in  XML configuration files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6v67-2wr5-gvf4</guid>
    </item>
    <item>
      <title>jvndb-2026-010300</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-010300</link>
      <description>&lt;p&gt;Hitachi Ops Center Viewpoint contain the following vulnerabilities:&#13;
&#13;
CVE-2014-3643, CVE-2023-3635, CVE-2023-6378, CVE-2023-6481, CVE-2023-35116, CVE-2024-12798, CVE-2024-12801, CVE-2024-47554&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Ops Center Viewpoint contain the following vulnerabilities:&#13;
&#13;
CVE-2014-3643, CVE-2023-3635, CVE-2023-6378, CVE-2023-6481, CVE-2023-35116, CVE-2024-12798, CVE-2024-12801, CVE-2024-47554&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-010300</guid>
    </item>
    <item>
      <title>OESA-2025-1082 — logback security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1082</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: logback, openEuler:22.03-LTS-SP3: logback, openEuler:22.03-LTS-SP4: logback, openEuler:24.03-LTS: logback, openEuler:24.03-LTS-SP1: logback&lt;/p&gt;
&lt;p&gt;Logback is intended as a successor to the popular log4j project.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core
      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows
      attacker to execute arbitrary code by compromising an existing
      logback configuration file or by injecting an environment variable
      before program execution.&lt;/p&gt;
&lt;p&gt;Malicious logback configuration files can allow the attacker to execute 
arbitrary code using the JaninoEventEvaluator extension.&lt;/p&gt;
&lt;p&gt;A successful attack requires the user to have write access to a 
configuration file. Alternatively, the attacker could inject a malicious 
environment variable pointing to a malicious configuration file. In both 
cases, the attack requires existing privilege.(CVE-2024-12798)&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to 
forge requests by compromising logback configuration files in XML.&lt;/p&gt;
&lt;p&gt;The attacks involves the modification of DOCTYPE declaration in  XML configuration files.(CVE-2024-12801)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: logback, openEuler:22.03-LTS-SP3: logback, openEuler:22.03-LTS-SP4: logback, openEuler:24.03-LTS: logback, openEuler:24.03-LTS-SP1: logback&lt;/p&gt;
&lt;p&gt;Logback is intended as a successor to the popular log4j project.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core
      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows
      attacker to execute arbitrary code by compromising an existing
      logback configuration file or by injecting an environment variable
      before program execution.&lt;/p&gt;
&lt;p&gt;Malicious logback configuration files can allow the attacker to execute 
arbitrary code using the JaninoEventEvaluator extension.&lt;/p&gt;
&lt;p&gt;A successful attack requires the user to have write access to a 
configuration file. Alternatively, the attacker could inject a malicious 
environment variable pointing to a malicious configuration file. In both 
cases, the attack requires existing privilege.(CVE-2024-12798)&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to 
forge requests by compromising logback configuration files in XML.&lt;/p&gt;
&lt;p&gt;The attacks involves the modification of DOCTYPE declaration in  XML configuration files.(CVE-2024-12801)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1082</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14627-1 — logback-1.2.11-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14627-1</link>
      <description>&lt;p&gt;logback-1.2.11-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;logback-1.2.11-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14627-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0072-1 — Security update for logback</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0072-1</link>
      <description>&lt;p&gt;Security update for logback&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for logback&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0072-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-12801</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12801</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:22.04:LTS: logback, Ubuntu:24.04:LTS: logback&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML. The attacks involves the modification of DOCTYPE declaration in  XML configuration files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:22.04:LTS: logback, Ubuntu:24.04:LTS: logback&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML. The attacks involves the modification of DOCTYPE declaration in  XML configuration files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12801</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0503 — Apache Cassandra: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0503</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Apache Cassandra ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Apache Cassandra ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0503</guid>
    </item>
  </channel>
</rss>
