<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:40:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-06274</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06274</link>
      <description>bdu:2024-06274</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06274</guid>
    </item>
    <item>
      <title>EUVD-2026-222402</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-222402</link>
      <description>EUVD-2026-222402</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-222402</guid>
    </item>
    <item>
      <title>fkie_cve-2024-36450</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-36450</link>
      <description>&lt;p&gt;Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-36450</guid>
    </item>
    <item>
      <title>GHSA-273g-8x52-9gmv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-273g-8x52-9gmv</link>
      <description>&lt;p&gt;Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-273g-8x52-9gmv</guid>
    </item>
    <item>
      <title>jvndb-2024-000059</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2024-000059</link>
      <description>&lt;p&gt;Multiple Webmin products contain multiple vulnerabilities listed below.&#13;
  * sysinfo.cgi is vulnerable to cross-site scripting (CWE-79)&#13;
    CVE-2024-36450&#13;
  * session_login.cgi is vulnerable to cross-site scripting (CWE-79)&#13;
    CVE-2024-36453&#13;
  * ajaxterm module is vulnerable to improper handling of insufficient permissions or privileges (CWE-280)&#13;
    CVE-2024-36451&#13;
  * ajaxterm module is vulnerable to cross-site request forgery (CWE-352)&#13;
    CVE-2024-36452&#13;
&#13;
CVE-2024-36450, CVE-2024-36451, CVE-2024-36452&#13;
Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2024-36453&#13;
hibiki moriyama of STNet, Incorporated reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Webmin products contain multiple vulnerabilities listed below.&#13;
  * sysinfo.cgi is vulnerable to cross-site scripting (CWE-79)&#13;
    CVE-2024-36450&#13;
  * session_login.cgi is vulnerable to cross-site scripting (CWE-79)&#13;
    CVE-2024-36453&#13;
  * ajaxterm module is vulnerable to improper handling of insufficient permissions or privileges (CWE-280)&#13;
    CVE-2024-36451&#13;
  * ajaxterm module is vulnerable to cross-site request forgery (CWE-352)&#13;
    CVE-2024-36452&#13;
&#13;
CVE-2024-36450, CVE-2024-36451, CVE-2024-36452&#13;
Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2024-36453&#13;
hibiki moriyama of STNet, Incorporated reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2024-000059</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1545 — Webmin: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1545</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Webmin ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und seine Rechte zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Webmin ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und seine Rechte zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1545</guid>
    </item>
  </channel>
</rss>
