<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:39:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-08854</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-08854</link>
      <description>bdu:2024-08854</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-08854</guid>
    </item>
    <item>
      <title>cisco-sa-fmc-sql-inj-LOYAFcfq — Cisco Secure Firewall Management Center Software SQL Injection Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-fmc-sql-inj-loyafcfq</link>
      <description>&lt;p&gt;Multiple vulnerabilities in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.&#13;
&#13;
These vulnerabilities exist because the web-based management interface does not validate user input adequately. An attacker could exploit these vulnerabilities by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit these vulnerabilities, an attacker would need Administrator-level privileges.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
&#13;
&#13;
This advisory is part of the October 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: October 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.&#13;
&#13;
These vulnerabilities exist because the web-based management interface does not validate user input adequately. An attacker could exploit these vulnerabilities by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit these vulnerabilities, an attacker would need Administrator-level privileges.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
&#13;
&#13;
This advisory is part of the October 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: October 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-fmc-sql-inj-loyafcfq</guid>
    </item>
    <item>
      <title>cnvd-2024-44495</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-44495</link>
      <description>cnvd-2024-44495</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-44495</guid>
    </item>
    <item>
      <title>EUVD-2026-197231</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-197231</link>
      <description>EUVD-2026-197231</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-197231</guid>
    </item>
    <item>
      <title>fkie_cve-2024-20472</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-20472</link>
      <description>&lt;p&gt;A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.&#13;
&#13;
This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.&#13;
&#13;
This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-20472</guid>
    </item>
    <item>
      <title>GHSA-253g-rphr-6h5j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-253g-rphr-6h5j</link>
      <description>&lt;p&gt;A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.&lt;/p&gt;
&lt;p&gt;This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.&lt;/p&gt;
&lt;p&gt;This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-253g-rphr-6h5j</guid>
    </item>
    <item>
      <title>gsd-2024-20472</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-20472</link>
      <description>gsd-2024-20472</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-20472</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3267 — Cisco Secure Firewall Management Center: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3267</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Cisco Secure Firewall Management Center ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, vertrauliche Informationen preiszugeben, beliebigen Code auszuführen, Daten zu manipulieren und erhöhte Rechte zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Cisco Secure Firewall Management Center ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, vertrauliche Informationen preiszugeben, beliebigen Code auszuführen, Daten zu manipulieren und erhöhte Rechte zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3267</guid>
    </item>
  </channel>
</rss>
