<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:19:26 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-08006</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08006</link>
      <description>bdu:2025-08006</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08006</guid>
    </item>
    <item>
      <title>cnvd-2025-22705</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-22705</link>
      <description>cnvd-2025-22705</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-22705</guid>
    </item>
    <item>
      <title>EUVD-2026-248973</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248973</link>
      <description>EUVD-2026-248973</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248973</guid>
    </item>
    <item>
      <title>fkie_cve-2025-52997</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52997</link>
      <description>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers could mount a brute-force attack to retrieve the passwords of all accounts in a given instance. This issue has been patched in version 2.34.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers could mount a brute-force attack to retrieve the passwords of all accounts in a given instance. This issue has been patched in version 2.34.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-52997</guid>
    </item>
    <item>
      <title>GHSA-cm2r-rg7r-p7gg — File Browser vulnerable to insecure password handling</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cm2r-rg7r-p7gg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;## Summary ##&lt;/p&gt;
&lt;p&gt;All user accounts authenticate towards a *File Browser* instance with a password. A missing password policy and brute-force protection makes it impossible for administrators to properly secure the authentication process.&lt;/p&gt;
&lt;p&gt;## Impact ##&lt;/p&gt;
&lt;p&gt;Attackers can mount a brute-force attack against the passwords of all accounts of an instance. Since the application is lacking the ability to prevent users from choosing a weak password, the attack is likely to succeed.&lt;/p&gt;
&lt;p&gt;## Vulnerability Description ##&lt;/p&gt;
&lt;p&gt;The application implement a classical authentication scheme using a username and password combination. While employed by many systems, this scheme is quite error-prone and a common cause for vulnerabilities. File Browser&amp;#39;s implementation has multiple weak points:&lt;/p&gt;
&lt;p&gt;1. Since the application is missing the capability for administrators to define a password policy, users are at liberty to set trivial and well-known passwords such as `secret` or even ones with only single digit like `1`.
2. New instances are set up with a default password of `admin` for the initial administrative account. This password is well known and easily guessable. While the documentation advises to change this password, the application does not technically enforce it.
3. The application does not implement any brute-force protection for the authentication endpoint. Attackers can make as many guesses for a password as the network bandwidth allows.&lt;/p&gt;
&lt;p&gt;The combination of these problems makes it likely, that an attac…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;## Summary ##&lt;/p&gt;
&lt;p&gt;All user accounts authenticate towards a *File Browser* instance with a password. A missing password policy and brute-force protection makes it impossible for administrators to properly secure the authentication process.&lt;/p&gt;
&lt;p&gt;## Impact ##&lt;/p&gt;
&lt;p&gt;Attackers can mount a brute-force attack against the passwords of all accounts of an instance. Since the application is lacking the ability to prevent users from choosing a weak password, the attack is likely to succeed.&lt;/p&gt;
&lt;p&gt;## Vulnerability Description ##&lt;/p&gt;
&lt;p&gt;The application implement a classical authentication scheme using a username and password combination. While employed by many systems, this scheme is quite error-prone and a common cause for vulnerabilities. File Browser&amp;#39;s implementation has multiple weak points:&lt;/p&gt;
&lt;p&gt;1. Since the application is missing the capability for administrators to define a password policy, users are at liberty to set trivial and well-known passwords such as `secret` or even ones with only single digit like `1`.
2. New instances are set up with a default password of `admin` for the initial administrative account. This password is well known and easily guessable. While the documentation advises to change this password, the application does not technically enforce it.
3. The application does not implement any brute-force protection for the authentication endpoint. Attackers can make as many guesses for a password as the network bandwidth allows.&lt;/p&gt;
&lt;p&gt;The combination of these problems makes it likely, that an attac…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cm2r-rg7r-p7gg</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</guid>
    </item>
  </channel>
</rss>
