<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:56:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-371429</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371429</link>
      <description>EUVD-2026-371429</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371429</guid>
    </item>
    <item>
      <title>fkie_cve-2026-66372</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66372</link>
      <description>&lt;p&gt;The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-66372</guid>
    </item>
    <item>
      <title>GHSA-gq5q-45hh-68cr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gq5q-45hh-68cr</link>
      <description>&lt;p&gt;The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gq5q-45hh-68cr</guid>
    </item>
    <item>
      <title>ICSA-26-258-01 — Digital Watchdog VMAX DVR and NVR Product Lineups</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-258-01</link>
      <description>&lt;p&gt;The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests. The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable. The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command. The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable. The affected products are missing authorization on state-changing CGIs and session checks are not performed. The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests. The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable. The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command. The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable. The affected products are missing authorization on state-changing CGIs and session checks are not performed. The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-258-01</guid>
    </item>
  </channel>
</rss>
