<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:04:15 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-05846</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05846</link>
      <description>bdu:2023-05846</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05846</guid>
    </item>
    <item>
      <title>EUVD-2026-244781</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-244781</link>
      <description>EUVD-2026-244781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-244781</guid>
    </item>
    <item>
      <title>fkie_cve-2023-29445</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-29445</link>
      <description>&lt;p&gt;An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-29445</guid>
    </item>
    <item>
      <title>GHSA-3hx8-rcv2-389f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3hx8-rcv2-389f</link>
      <description>&lt;p&gt;An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3hx8-rcv2-389f</guid>
    </item>
    <item>
      <title>gsd-2023-29445</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-29445</link>
      <description>gsd-2023-29445</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-29445</guid>
    </item>
    <item>
      <title>ICSA-23-243-03 — PTC Kepware KepServerEX (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-243-03</link>
      <description>&lt;p&gt;The installer application of KEPServerEX is vulnerable to DLL search order hijacking. This could allow an adversary to repackage the installer with a malicious DLL and trick users into installing the trojanized software. Successful exploitation could lead to code execution with administrator privileges. KEPServerEX binary is vulnerable to DLL search order hijacking. A locally authenticated adversary could escalate privileges to administrator by planting a malicious DLL in a specific directory. KEPServerEx is vulnerable to UNC path injection via a malicious project file. By tricking a user into loading a project file and clicking a specific button in the GUI, an adversary could obtain Windows user NTLMv2 hashes, and crack them offline. The KEPServerEX Configuration web server uses basic authentication to protect user credentials. An adversary could perform a man-in-the-middle (MitM) attack via ARP spoofing to obtain the web server&amp;#39;s plaintext credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The installer application of KEPServerEX is vulnerable to DLL search order hijacking. This could allow an adversary to repackage the installer with a malicious DLL and trick users into installing the trojanized software. Successful exploitation could lead to code execution with administrator privileges. KEPServerEX binary is vulnerable to DLL search order hijacking. A locally authenticated adversary could escalate privileges to administrator by planting a malicious DLL in a specific directory. KEPServerEx is vulnerable to UNC path injection via a malicious project file. By tricking a user into loading a project file and clicking a specific button in the GUI, an adversary could obtain Windows user NTLMv2 hashes, and crack them offline. The KEPServerEX Configuration web server uses basic authentication to protect user credentials. An adversary could perform a man-in-the-middle (MitM) attack via ARP spoofing to obtain the web server&amp;#39;s plaintext credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-243-03</guid>
    </item>
  </channel>
</rss>
