<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:20:44 +0000</lastBuildDate>
    <item>
      <title>cnvd-2019-14090</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-14090</link>
      <description>cnvd-2019-14090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-14090</guid>
    </item>
    <item>
      <title>EUVD-2026-324096</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-324096</link>
      <description>EUVD-2026-324096</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-324096</guid>
    </item>
    <item>
      <title>fkie_cve-2017-14728</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-14728</link>
      <description>&lt;p&gt;An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication open to public.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication open to public.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-14728</guid>
    </item>
    <item>
      <title>GHSA-8ghv-f82m-w39j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8ghv-f82m-w39j</link>
      <description>&lt;p&gt;An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication open to public.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication open to public.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8ghv-f82m-w39j</guid>
    </item>
    <item>
      <title>gsd-2017-14728</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-14728</link>
      <description>gsd-2017-14728</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-14728</guid>
    </item>
    <item>
      <title>ICSA-19-122-01 — Orpak SiteOmat</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-122-01</link>
      <description>&lt;p&gt;The application utilizes hard coded username and password credentials for application login.CVE-2017-14728 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The application web interface does not properly neutralize user-controllable input, which could allow cross-site scripting.CVE-2017-14850 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). The application does not properly sanitize external input, which may allow an attacker to access the product by specially crafted input.CVE-2017-14851 has been assigned to this vulnerability. A CVSS v3 base score of 9.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). The application transmits information in plain text, including credentials, which could allow an attacker with access to transmitted data to obtain credentials and bypass authentication.CVE-2017-14852 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L). The application does not properly restrict syntax from external input, which could allow unauthenticated users to execute specially crafted code on the target system.CVE-2017-14853 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been assigned; the CVSS vect…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The application utilizes hard coded username and password credentials for application login.CVE-2017-14728 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The application web interface does not properly neutralize user-controllable input, which could allow cross-site scripting.CVE-2017-14850 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). The application does not properly sanitize external input, which may allow an attacker to access the product by specially crafted input.CVE-2017-14851 has been assigned to this vulnerability. A CVSS v3 base score of 9.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). The application transmits information in plain text, including credentials, which could allow an attacker with access to transmitted data to obtain credentials and bypass authentication.CVE-2017-14852 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L). The application does not properly restrict syntax from external input, which could allow unauthenticated users to execute specially crafted code on the target system.CVE-2017-14853 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been assigned; the CVSS vect…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-122-01</guid>
    </item>
  </channel>
</rss>
