<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 07:05:38 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-05311</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05311</link>
      <description>bdu:2022-05311</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05311</guid>
    </item>
    <item>
      <title>EUVD-2026-18940</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-18940</link>
      <description>EUVD-2026-18940</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-18940</guid>
    </item>
    <item>
      <title>fkie_cve-2022-38078</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-38078</link>
      <description>&lt;p&gt;Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected products and versions are as follows: Movable Type 7 r.5202 and earlier, Movable Type Advanced 7 r.5202 and earlier, Movable Type 6.8.6 and earlier, Movable Type Advanced 6.8.6 and earlier, Movable Type Premium 1.52 and earlier, and Movable Type Premium Advanced 1.52 and earlier. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected products and versions are as follows: Movable Type 7 r.5202 and earlier, Movable Type Advanced 7 r.5202 and earlier, Movable Type 6.8.6 and earlier, Movable Type Advanced 6.8.6 and earlier, Movable Type Premium 1.52 and earlier, and Movable Type Premium Advanced 1.52 and earlier. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-38078</guid>
    </item>
    <item>
      <title>GHSA-f342-4q2c-v2q2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f342-4q2c-v2q2</link>
      <description>&lt;p&gt;Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected products and versions are as follows: Movable Type 7 r.5202 and earlier, Movable Type Advanced 7 r.5202 and earlier, Movable Type 6.8.6 and earlier, Movable Type Advanced 6.8.6 and earlier, Movable Type Premium 1.52 and earlier, and Movable Type Premium Advanced 1.52 and earlier. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected products and versions are as follows: Movable Type 7 r.5202 and earlier, Movable Type Advanced 7 r.5202 and earlier, Movable Type 6.8.6 and earlier, Movable Type Advanced 6.8.6 and earlier, Movable Type Premium 1.52 and earlier, and Movable Type Premium Advanced 1.52 and earlier. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f342-4q2c-v2q2</guid>
    </item>
    <item>
      <title>gsd-2022-38078</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-38078</link>
      <description>gsd-2022-38078</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-38078</guid>
    </item>
    <item>
      <title>jvndb-2022-000064</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2022-000064</link>
      <description>&lt;p&gt;Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability (CWE-74).&#13;
Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it.&#13;
According to the developer, it is unable to execute a command with an arbitrary value added to its argument, even if the vulnerability is exploited.&#13;
&#13;
Osaka University of Economics reported this vulnerability to Six Apart Ltd. and coordinated. Six Apart Ltd. and JPCERT/CC published respective advisories in order to notify users of this vulnerability.&#13;
&#13;
And almost at the same time, SHIGA TAKUMA of BroadBand Security, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with Six Apart Ltd. under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability (CWE-74).&#13;
Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it.&#13;
According to the developer, it is unable to execute a command with an arbitrary value added to its argument, even if the vulnerability is exploited.&#13;
&#13;
Osaka University of Economics reported this vulnerability to Six Apart Ltd. and coordinated. Six Apart Ltd. and JPCERT/CC published respective advisories in order to notify users of this vulnerability.&#13;
&#13;
And almost at the same time, SHIGA TAKUMA of BroadBand Security, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with Six Apart Ltd. under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2022-000064</guid>
    </item>
  </channel>
</rss>
