<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 23:34:01 +0000</lastBuildDate>
    <item>
      <title>bdu:2018-01194</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2018-01194</link>
      <description>bdu:2018-01194</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2018-01194</guid>
    </item>
    <item>
      <title>cnvd-2018-21173</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-21173</link>
      <description>cnvd-2018-21173</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-21173</guid>
    </item>
    <item>
      <title>EUVD-2026-167623</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-167623</link>
      <description>EUVD-2026-167623</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-167623</guid>
    </item>
    <item>
      <title>fkie_cve-2018-14810</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-14810</link>
      <description>&lt;p&gt;WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior parse files and pass invalidated user data to an unsafe method call, which may allow code to be executed in the context of an administrator.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior parse files and pass invalidated user data to an unsafe method call, which may allow code to be executed in the context of an administrator.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-14810</guid>
    </item>
    <item>
      <title>GHSA-5f5v-7w3c-2rm9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5f5v-7w3c-2rm9</link>
      <description>&lt;p&gt;WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior parse files and pass invalidated user data to an unsafe method call, which may allow code to be executed in the context of an administrator.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior parse files and pass invalidated user data to an unsafe method call, which may allow code to be executed in the context of an administrator.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5f5v-7w3c-2rm9</guid>
    </item>
    <item>
      <title>gsd-2018-14810</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-14810</link>
      <description>gsd-2018-14810</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-14810</guid>
    </item>
    <item>
      <title>ICSA-18-277-01 — WECON PI Studio (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-18-277-01</link>
      <description>&lt;p&gt;When parsing specific files the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code under the context of an administrator.CVE-2018-14818 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). When parsing specific files the process does not properly validate user-supplied data, which can result in multiple write instances past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of an administrator.CVE-2018-14810 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). When parsing project files the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.CVE-2018-17889 has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). When parsing specific files the process does not properly validate user-supplied data, which can result in a read past the end of an allocated object. CVE-2018-14814 has been assigned to this vulnerability. A CVSS v3 base score of 3.3 has been calculated; the CVSS vector string is (AV:L/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When parsing specific files the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code under the context of an administrator.CVE-2018-14818 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). When parsing specific files the process does not properly validate user-supplied data, which can result in multiple write instances past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of an administrator.CVE-2018-14810 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). When parsing project files the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.CVE-2018-17889 has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). When parsing specific files the process does not properly validate user-supplied data, which can result in a read past the end of an allocated object. CVE-2018-14814 has been assigned to this vulnerability. A CVSS v3 base score of 3.3 has been calculated; the CVSS vector string is (AV:L/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-18-277-01</guid>
    </item>
  </channel>
</rss>
