<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 11:03:07 +0000</lastBuildDate>
    <item>
      <title>cnvd-2022-08192</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-08192</link>
      <description>cnvd-2022-08192</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-08192</guid>
    </item>
    <item>
      <title>EUVD-2026-13914</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-13914</link>
      <description>EUVD-2026-13914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-13914</guid>
    </item>
    <item>
      <title>fkie_cve-2022-23857</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23857</link>
      <description>&lt;p&gt;model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users&amp;#39; encrypted passwords).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users&amp;#39; encrypted passwords).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-23857</guid>
    </item>
    <item>
      <title>GHSA-pmcr-2rhp-36hr — SQL injection in github.com/navidrome/navidrome</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pmcr-2rhp-36hr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/navidrome/navidrome&lt;/p&gt;
&lt;p&gt;model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users&amp;#39; encrypted passwords).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/navidrome/navidrome&lt;/p&gt;
&lt;p&gt;model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users&amp;#39; encrypted passwords).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pmcr-2rhp-36hr</guid>
    </item>
    <item>
      <title>gsd-2022-23857</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-23857</link>
      <description>gsd-2022-23857</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-23857</guid>
    </item>
  </channel>
</rss>
