<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:13:04 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-337084</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337084</link>
      <description>EUVD-2026-337084</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337084</guid>
    </item>
    <item>
      <title>fkie_cve-2025-34176</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-34176</link>
      <description>&lt;p&gt;In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least &amp;#34;WebCfg - Services: suricata package&amp;#34; permissions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least &amp;#34;WebCfg - Services: suricata package&amp;#34; permissions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-34176</guid>
    </item>
    <item>
      <title>GHSA-4fgr-95mh-x7h2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4fgr-95mh-x7h2</link>
      <description>&lt;p&gt;In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least &amp;#34;WebCfg - Services: suricata package&amp;#34; permissions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least &amp;#34;WebCfg - Services: suricata package&amp;#34; permissions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4fgr-95mh-x7h2</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2016 — Netgate pfSense: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2016</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Netgate pfSense ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen  und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Netgate pfSense ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen  und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2016</guid>
    </item>
  </channel>
</rss>
