<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:02:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-06440</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06440</link>
      <description>bdu:2024-06440</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06440</guid>
    </item>
    <item>
      <title>EUVD-2026-199823</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-199823</link>
      <description>EUVD-2026-199823</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-199823</guid>
    </item>
    <item>
      <title>fkie_cve-2024-36453</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-36453</link>
      <description>&lt;p&gt;Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-36453</guid>
    </item>
    <item>
      <title>GHSA-w2jv-599h-mr48</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w2jv-599h-mr48</link>
      <description>&lt;p&gt;Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w2jv-599h-mr48</guid>
    </item>
    <item>
      <title>jvndb-2024-000059</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2024-000059</link>
      <description>&lt;p&gt;Multiple Webmin products contain multiple vulnerabilities listed below.&#13;
  * sysinfo.cgi is vulnerable to cross-site scripting (CWE-79)&#13;
    CVE-2024-36450&#13;
  * session_login.cgi is vulnerable to cross-site scripting (CWE-79)&#13;
    CVE-2024-36453&#13;
  * ajaxterm module is vulnerable to improper handling of insufficient permissions or privileges (CWE-280)&#13;
    CVE-2024-36451&#13;
  * ajaxterm module is vulnerable to cross-site request forgery (CWE-352)&#13;
    CVE-2024-36452&#13;
&#13;
CVE-2024-36450, CVE-2024-36451, CVE-2024-36452&#13;
Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2024-36453&#13;
hibiki moriyama of STNet, Incorporated reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Webmin products contain multiple vulnerabilities listed below.&#13;
  * sysinfo.cgi is vulnerable to cross-site scripting (CWE-79)&#13;
    CVE-2024-36450&#13;
  * session_login.cgi is vulnerable to cross-site scripting (CWE-79)&#13;
    CVE-2024-36453&#13;
  * ajaxterm module is vulnerable to improper handling of insufficient permissions or privileges (CWE-280)&#13;
    CVE-2024-36451&#13;
  * ajaxterm module is vulnerable to cross-site request forgery (CWE-352)&#13;
    CVE-2024-36452&#13;
&#13;
CVE-2024-36450, CVE-2024-36451, CVE-2024-36452&#13;
Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2024-36453&#13;
hibiki moriyama of STNet, Incorporated reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2024-000059</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1545 — Webmin: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1545</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Webmin ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und seine Rechte zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Webmin ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und seine Rechte zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1545</guid>
    </item>
  </channel>
</rss>
