<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 18:53:39 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-53515 — Advantech iView SQL Injection</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-53515</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Advantech iView&lt;/p&gt;
&lt;p&gt;A vulnerability exists in Advantech iView that allows for SQL injection 
and remote code execution through NetworkServlet.archiveTrap(). This 
issue requires an authenticated attacker with at least user-level 
privileges. Certain input parameters are not sanitized, allowing an 
attacker to perform SQL injection and potentially execute code in the 
context of the &amp;#39;nt authority\local service&amp;#39; account.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Advantech iView&lt;/p&gt;
&lt;p&gt;A vulnerability exists in Advantech iView that allows for SQL injection 
and remote code execution through NetworkServlet.archiveTrap(). This 
issue requires an authenticated attacker with at least user-level 
privileges. Certain input parameters are not sanitized, allowing an 
attacker to perform SQL injection and potentially execute code in the 
context of the &amp;#39;nt authority\local service&amp;#39; account.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-53515</guid>
    </item>
    <item>
      <title>ICSA-25-191-08 — Advantech iView</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-191-08</link>
      <description>&lt;p&gt;A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user&amp;#39;s browser, potentially leading to information disclosure or other malicious activities. A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user&amp;#39;s browser, potentially leading to information disclosure or other malicious activities. A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user&amp;#39;s browser, potentially leading to information disclosure or other malicious activities. A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure or a denial-of-service condition. A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privilege…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user&amp;#39;s browser, potentially leading to information disclosure or other malicious activities. A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user&amp;#39;s browser, potentially leading to information disclosure or other malicious activities. A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user&amp;#39;s browser, potentially leading to information disclosure or other malicious activities. A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure or a denial-of-service condition. A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privilege…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-191-08</guid>
    </item>
  </channel>
</rss>
