<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 22:19:31 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-01019</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-01019</link>
      <description>bdu:2022-01019</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-01019</guid>
    </item>
    <item>
      <title>EUVD-2026-67916</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-67916</link>
      <description>EUVD-2026-67916</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-67916</guid>
    </item>
    <item>
      <title>fkie_cve-2018-16202</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-16202</link>
      <description>&lt;p&gt;Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-16202</guid>
    </item>
    <item>
      <title>GHSA-xwjh-cp99-cj8q — Path Traversal in cordova-plugin-ionic-webview</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xwjh-cp99-cj8q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: cordova-plugin-ionic-webview&lt;/p&gt;
&lt;p&gt;Versions of `cordova-plugin-ionic-webview` prior to 2.2.0 are vulnerable to Path Traversal, allowing attackers access to OS local files that should be inaccessible by third-party applications.  The package launches a webserver listening on http://localhost:8080 without restricting access of the app itself, thus escaping the iOS application sandbox and accessing local files.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Upgrade to version 2.2.0&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: cordova-plugin-ionic-webview&lt;/p&gt;
&lt;p&gt;Versions of `cordova-plugin-ionic-webview` prior to 2.2.0 are vulnerable to Path Traversal, allowing attackers access to OS local files that should be inaccessible by third-party applications.  The package launches a webserver listening on http://localhost:8080 without restricting access of the app itself, thus escaping the iOS application sandbox and accessing local files.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Upgrade to version 2.2.0&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xwjh-cp99-cj8q</guid>
    </item>
    <item>
      <title>gsd-2018-16202</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-16202</link>
      <description>gsd-2018-16202</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-16202</guid>
    </item>
    <item>
      <title>ICSA-22-025-01 — GE Gas Power ToolBoxST</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-025-01</link>
      <description>&lt;p&gt;GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project/template file.CVE-2021-44477 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). ToolBoxST prior to Version 7.8.0 uses a vulnerable version of the Ionic .NET Zip library that does not properly sanitize path names allowing files to be extracted to a location above their parent directory and back to the root directory. If an attacker compromises an HMI or creates their own SDI client, they can upload the device.zip file from a controller, patch it to contain a malicious file and path, and download it back to the controller. The next user to perform an upload could grab the malicious device.zip and extract it to their HMI, creating the potential for arbitrary write, overwrite, and execution.CVE-2018-16202 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project/template file.CVE-2021-44477 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). ToolBoxST prior to Version 7.8.0 uses a vulnerable version of the Ionic .NET Zip library that does not properly sanitize path names allowing files to be extracted to a location above their parent directory and back to the root directory. If an attacker compromises an HMI or creates their own SDI client, they can upload the device.zip file from a controller, patch it to contain a malicious file and path, and download it back to the controller. The next user to perform an upload could grab the malicious device.zip and extract it to their HMI, creating the potential for arbitrary write, overwrite, and execution.CVE-2018-16202 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-025-01</guid>
    </item>
    <item>
      <title>jvndb-2018-000133</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2018-000133</link>
      <description>&lt;p&gt;cordova-plugin-ionic-webview provided by npm, Inc. contains a path traversal vulnerability (CWE-22) .&#13;
&#13;
This vulnerability was first reported to npm, Inc. by the below reporters then also reported to IPA. Based on the coordination request made by the reporters, JPCERT/CC coordinated with npm, Inc. and published this advisory on JVN.&#13;
&#13;
Reporters: Tatsuya Sakamto and Gaku Mochizuki of Mitsui Bussan Secure Directions, Inc.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cordova-plugin-ionic-webview provided by npm, Inc. contains a path traversal vulnerability (CWE-22) .&#13;
&#13;
This vulnerability was first reported to npm, Inc. by the below reporters then also reported to IPA. Based on the coordination request made by the reporters, JPCERT/CC coordinated with npm, Inc. and published this advisory on JVN.&#13;
&#13;
Reporters: Tatsuya Sakamto and Gaku Mochizuki of Mitsui Bussan Secure Directions, Inc.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2018-000133</guid>
    </item>
  </channel>
</rss>
