<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:26:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-01852</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-01852</link>
      <description>bdu:2019-01852</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-01852</guid>
    </item>
    <item>
      <title>certfr-2019-avi-083 — De multiples vulnérabilités ont été découvertes dans Aruba Instant.
Elles permettent à un attaquant de provoquer une ex…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-083</link>
      <description>certfr-2019-avi-083</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-083</guid>
    </item>
    <item>
      <title>cnvd-2019-06345</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-06345</link>
      <description>cnvd-2019-06345</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-06345</guid>
    </item>
    <item>
      <title>EUVD-2026-63037</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-63037</link>
      <description>EUVD-2026-63037</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-63037</guid>
    </item>
    <item>
      <title>fkie_cve-2018-7064</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-7064</link>
      <description>&lt;p&gt;A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or expose the session cookie for an administrative session. Workaround: Administrators should make sure they log out of the Aruba Instant UI when not actively managing the system, and should use caution clicking links from external sources while logged into the IAP administrative interface. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or expose the session cookie for an administrative session. Workaround: Administrators should make sure they log out of the Aruba Instant UI when not actively managing the system, and should use caution clicking links from external sources while logged into the IAP administrative interface. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-7064</guid>
    </item>
    <item>
      <title>GHSA-h438-gvrc-w5f9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h438-gvrc-w5f9</link>
      <description>&lt;p&gt;A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or expose the session cookie for an administrative session. Workaround: Administrators should make sure they log out of the Aruba Instant UI when not actively managing the system, and should use caution clicking links from external sources while logged into the IAP administrative interface. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or expose the session cookie for an administrative session. Workaround: Administrators should make sure they log out of the Aruba Instant UI when not actively managing the system, and should use caution clicking links from external sources while logged into the IAP administrative interface. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h438-gvrc-w5f9</guid>
    </item>
    <item>
      <title>gsd-2018-7064</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-7064</link>
      <description>gsd-2018-7064</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-7064</guid>
    </item>
    <item>
      <title>ICSA-19-134-07 — ICSA-19-134-07 Siemens SCALANCE W1750D</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-134-07</link>
      <description>&lt;p&gt;A command injection vulnerability is present that permits an unauthenticated user with access to the web interface of the affected device to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. The security vulnerability could be exploited by an attacker with network access to the affected system. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality, integrity and availability of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known. A vulnerability exists in the affected devices that allows an unauthenticated attacker to access core dumps of previously crashed processes through the web interface of the device. The security vulnerability could be exploited by an attacker with network access to the affected system. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known. A vulnerability is present which allows an unauthenticated user to retrieve recently cached configuration commands by sending a crafted URL to the web interface of an affected device. The security v…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A command injection vulnerability is present that permits an unauthenticated user with access to the web interface of the affected device to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. The security vulnerability could be exploited by an attacker with network access to the affected system. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality, integrity and availability of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known. A vulnerability exists in the affected devices that allows an unauthenticated attacker to access core dumps of previously crashed processes through the web interface of the device. The security vulnerability could be exploited by an attacker with network access to the affected system. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known. A vulnerability is present which allows an unauthenticated user to retrieve recently cached configuration commands by sending a crafted URL to the web interface of an affected device. The security v…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-134-07</guid>
    </item>
  </channel>
</rss>
