<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:40:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-06316</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06316</link>
      <description>bdu:2025-06316</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06316</guid>
    </item>
    <item>
      <title>EUVD-2026-273135</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-273135</link>
      <description>EUVD-2026-273135</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-273135</guid>
    </item>
    <item>
      <title>fkie_cve-2025-29813</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-29813</link>
      <description>&lt;p&gt;Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-29813</guid>
    </item>
    <item>
      <title>GHSA-jhcc-gwm2-46v7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jhcc-gwm2-46v7</link>
      <description>&lt;p&gt;An elevation of privilege vulnerability exists when Visual Studio improperly handles pipeline job tokens. An attacker who successfully exploited this vulnerability could extend their access to a project.
To exploit this vulnerability, an attacker would first have to have access to the project and swap the short-term token for a long-term one.
The update addresses the vulnerability by correcting how the Visual Studio updater handles these tokens.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An elevation of privilege vulnerability exists when Visual Studio improperly handles pipeline job tokens. An attacker who successfully exploited this vulnerability could extend their access to a project.
To exploit this vulnerability, an attacker would first have to have access to the project and swap the short-term token for a long-term one.
The update addresses the vulnerability by correcting how the Visual Studio updater handles these tokens.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jhcc-gwm2-46v7</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-29813 — Azure DevOps Elevation of Privilege Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-29813</link>
      <description>msrc_CVE-2025-29813</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-29813</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1015 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1015</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, Microsoft Visual Studio Code, Microsoft Azure DevOps und Microsoft .NET Framework ausnutzen, um seine Privilegien zu eskalieren, Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, beliebigen Programmcode auszuführen oder Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio, Microsoft Visual Studio Code, Microsoft Azure DevOps und Microsoft .NET Framework ausnutzen, um seine Privilegien zu eskalieren, Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, beliebigen Programmcode auszuführen oder Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1015</guid>
    </item>
  </channel>
</rss>
