<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:16:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15985</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15985</link>
      <description>bdu:2025-15985</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15985</guid>
    </item>
    <item>
      <title>EUVD-2026-275245</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275245</link>
      <description>EUVD-2026-275245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275245</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40800</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40800</link>
      <description>&lt;p&gt;A vulnerability has been identified in COMOS V10.6 (All versions &amp;lt; V10.6.1), COMOS V10.6 (All versions &amp;lt; V10.6.1), NX V2412 (All versions &amp;lt; V2412.8700), NX V2506 (All versions &amp;lt; V2506.6000), Simcenter 3D (All versions &amp;lt; V2506.6000), Simcenter Femap (All versions &amp;lt; V2506.0002), Solid Edge SE2025 (All versions &amp;lt; V225.0 Update 10), Solid Edge SE2026 (All versions &amp;lt; V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in COMOS V10.6 (All versions &amp;lt; V10.6.1), COMOS V10.6 (All versions &amp;lt; V10.6.1), NX V2412 (All versions &amp;lt; V2412.8700), NX V2506 (All versions &amp;lt; V2506.6000), Simcenter 3D (All versions &amp;lt; V2506.6000), Simcenter Femap (All versions &amp;lt; V2506.0002), Solid Edge SE2025 (All versions &amp;lt; V225.0 Update 10), Solid Edge SE2026 (All versions &amp;lt; V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40800</guid>
    </item>
    <item>
      <title>GHSA-xg9v-jc69-p54f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xg9v-jc69-p54f</link>
      <description>&lt;p&gt;A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), NX V2412 (All versions &amp;lt; V2412.8700), NX V2506 (All versions &amp;lt; V2506.6000), Simcenter 3D (All versions &amp;lt; V2506.6000), Simcenter Femap (All versions &amp;lt; V2506.0002), Solid Edge SE2025 (All versions &amp;lt; V225.0 Update 10), Solid Edge SE2026 (All versions &amp;lt; V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), NX V2412 (All versions &amp;lt; V2412.8700), NX V2506 (All versions &amp;lt; V2506.6000), Simcenter 3D (All versions &amp;lt; V2506.6000), Simcenter Femap (All versions &amp;lt; V2506.0002), Solid Edge SE2025 (All versions &amp;lt; V225.0 Update 10), Solid Edge SE2026 (All versions &amp;lt; V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xg9v-jc69-p54f</guid>
    </item>
    <item>
      <title>ICSA-25-345-04 — Siemens IAM Client</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-345-04</link>
      <description>&lt;p&gt;The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-345-04</guid>
    </item>
    <item>
      <title>SSA-212953 — SSA-212953: Multiple Vulnerabilities in COMOS</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-212953</link>
      <description>&lt;p&gt;When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password. DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. curl&amp;#39;s websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.&lt;/p&gt;
&lt;p&gt;A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy. The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-mid…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password. DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. curl&amp;#39;s websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.&lt;/p&gt;
&lt;p&gt;A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy. The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-mid…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-212953</guid>
    </item>
  </channel>
</rss>
