<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 00:23:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-51594</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-51594</link>
      <description>EUVD-2026-51594</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-51594</guid>
    </item>
    <item>
      <title>fkie_cve-2019-7671</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-7671</link>
      <description>&lt;p&gt;Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-7671</guid>
    </item>
    <item>
      <title>GHSA-6857-8pq4-3jcg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6857-8pq4-3jcg</link>
      <description>&lt;p&gt;Prima Systems FlexAir devices allow Authenticated Stored XSS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Prima Systems FlexAir devices allow Authenticated Stored XSS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6857-8pq4-3jcg</guid>
    </item>
    <item>
      <title>gsd-2019-7671</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-7671</link>
      <description>gsd-2019-7671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-7671</guid>
    </item>
    <item>
      <title>ICSA-19-211-02 — Prima Systems FlexAir</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-211-02</link>
      <description>&lt;p&gt;The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.CVE-2019-7670 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application &amp;#39;s web root with root privileges.CVE-2019-7669 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.CVE-2019-7281 has been assigned to this vulnerability. A CVSS v3 base score of 5.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L). The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.CVE-2019-7280 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Parameters sent to scripts are not…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.CVE-2019-7670 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application &amp;#39;s web root with root privileges.CVE-2019-7669 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.CVE-2019-7281 has been assigned to this vulnerability. A CVSS v3 base score of 5.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L). The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.CVE-2019-7280 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Parameters sent to scripts are not…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-211-02</guid>
    </item>
  </channel>
</rss>
