<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:30:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-351392</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351392</link>
      <description>EUVD-2026-351392</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351392</guid>
    </item>
    <item>
      <title>fkie_cve-2025-41771</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41771</link>
      <description>&lt;p&gt;An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-41771</guid>
    </item>
    <item>
      <title>GHSA-vr3r-mcqv-4cmg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vr3r-mcqv-4cmg</link>
      <description>&lt;p&gt;An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vr3r-mcqv-4cmg</guid>
    </item>
    <item>
      <title>vde-2025-056 — Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-056</link>
      <description>&lt;p&gt;This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-056</guid>
    </item>
  </channel>
</rss>
