<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 00:24:50 +0000</lastBuildDate>
    <item>
      <title>cnvd-2019-21065</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-21065</link>
      <description>cnvd-2019-21065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-21065</guid>
    </item>
    <item>
      <title>EUVD-2026-51545</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-51545</link>
      <description>EUVD-2026-51545</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-51545</guid>
    </item>
    <item>
      <title>fkie_cve-2019-7666</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-7666</link>
      <description>&lt;p&gt;Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-7666</guid>
    </item>
    <item>
      <title>GHSA-2j6j-xh5r-gf2p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2j6j-xh5r-gf2p</link>
      <description>&lt;p&gt;Prima Systems FlexAir devices allow authentication with MD5 hashes directly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Prima Systems FlexAir devices allow authentication with MD5 hashes directly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2j6j-xh5r-gf2p</guid>
    </item>
    <item>
      <title>gsd-2019-7666</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-7666</link>
      <description>gsd-2019-7666</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-7666</guid>
    </item>
    <item>
      <title>ICSA-19-211-02 — Prima Systems FlexAir</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-211-02</link>
      <description>&lt;p&gt;The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.CVE-2019-7670 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application &amp;#39;s web root with root privileges.CVE-2019-7669 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.CVE-2019-7281 has been assigned to this vulnerability. A CVSS v3 base score of 5.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L). The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.CVE-2019-7280 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Parameters sent to scripts are not…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.CVE-2019-7670 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application &amp;#39;s web root with root privileges.CVE-2019-7669 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.CVE-2019-7281 has been assigned to this vulnerability. A CVSS v3 base score of 5.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L). The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.CVE-2019-7280 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Parameters sent to scripts are not…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-211-02</guid>
    </item>
  </channel>
</rss>
