<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:53:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15896</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15896</link>
      <description>bdu:2025-15896</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15896</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1079 — De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1079</link>
      <description>certfr-2025-avi-1079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1079</guid>
    </item>
    <item>
      <title>EUVD-2026-262937</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262937</link>
      <description>EUVD-2026-262937</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262937</guid>
    </item>
    <item>
      <title>fkie_cve-2025-42872</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-42872</link>
      <description>&lt;p&gt;Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-42872</guid>
    </item>
    <item>
      <title>GHSA-4f68-6cfp-mfcj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4f68-6cfp-mfcj</link>
      <description>&lt;p&gt;Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4f68-6cfp-mfcj</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2768 — SAP Patchday Dezember 2025: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2768</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in SAP ausnutzen, um beliebigen Code auszuführen, Systeme zu übernehmen, sensible Daten abzuziehen, interne Ressourcen über SSRF anzusteuern, Dienste zum Absturz zu bringen oder Autorisierungsgrenzen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in SAP ausnutzen, um beliebigen Code auszuführen, Systeme zu übernehmen, sensible Daten abzuziehen, interne Ressourcen über SSRF anzusteuern, Dienste zum Absturz zu bringen oder Autorisierungsgrenzen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2768</guid>
    </item>
  </channel>
</rss>
