<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:44:34 +0000</lastBuildDate>
    <item>
      <title>cnvd-2017-06642</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-06642</link>
      <description>cnvd-2017-06642</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-06642</guid>
    </item>
    <item>
      <title>EUVD-2026-178815</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-178815</link>
      <description>EUVD-2026-178815</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-178815</guid>
    </item>
    <item>
      <title>fkie_cve-2016-6812</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-6812</link>
      <description>&lt;p&gt;The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-6812</guid>
    </item>
    <item>
      <title>GHSA-vw2c-5wph-v92r — Improper Neutralization of Input During Web Page Generation in Apache CXF</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vw2c-5wph-v92r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-core&lt;/p&gt;
&lt;p&gt;The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.cxf:cxf-core&lt;/p&gt;
&lt;p&gt;The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vw2c-5wph-v92r</guid>
    </item>
    <item>
      <title>gsd-2016-6812</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-6812</link>
      <description>gsd-2016-6812</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-6812</guid>
    </item>
    <item>
      <title>RHSA-2017:0868 — Red Hat Security Advisory: Red Hat JBoss Fuse/A-MQ 6.3 R2 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:0868</link>
      <description>&lt;p&gt;jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name elasticsearch: remote code execution via Groovy sandbox bypass ActiveMQ: DoS in client via shutdown command apache-cxf: XSS in Apache CXF FormattedServiceListWriter Groovy: Remote code execution via deserialization apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE Spark: Directory traversal vulnerability in version 2.5 swagger-ui: cross-site scripting in key names camel-snakeyaml: Unmarshalling operation is vulnerable to RCE&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name elasticsearch: remote code execution via Groovy sandbox bypass ActiveMQ: DoS in client via shutdown command apache-cxf: XSS in Apache CXF FormattedServiceListWriter Groovy: Remote code execution via deserialization apache-cxf: Atom entity provider of Apache CXF JAX-RS is vulnerable to XXE Spark: Directory traversal vulnerability in version 2.5 swagger-ui: cross-site scripting in key names camel-snakeyaml: Unmarshalling operation is vulnerable to RCE&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:0868</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0180 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</guid>
    </item>
  </channel>
</rss>
