<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:04:15 +0000</lastBuildDate>
    <item>
      <title>cnvd-2026-03181</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-03181</link>
      <description>cnvd-2026-03181</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-03181</guid>
    </item>
    <item>
      <title>EUVD-2026-230708</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-230708</link>
      <description>EUVD-2026-230708</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-230708</guid>
    </item>
    <item>
      <title>fkie_cve-2025-25276</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-25276</link>
      <description>&lt;p&gt;An unauthenticated attacker can hijack other users&amp;#39; devices and potentially control them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated attacker can hijack other users&amp;#39; devices and potentially control them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-25276</guid>
    </item>
    <item>
      <title>GHSA-458q-4x98-hjwr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-458q-4x98-hjwr</link>
      <description>&lt;p&gt;An unauthenticated attacker can hijack other users&amp;#39; devices and potentially control them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated attacker can hijack other users&amp;#39; devices and potentially control them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-458q-4x98-hjwr</guid>
    </item>
    <item>
      <title>ICSA-25-105-04 — Growatt Cloud Applications</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-105-04</link>
      <description>&lt;p&gt;An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value while adding or editing a plant. An unauthenticated attacker can check the existence of usernames in the system by querying an API. An authenticated attacker can obtain any plant name by knowing the plant ID. An unauthenticated attacker can obtain a user&amp;#39;s plant list by knowing the username. An unauthenticated attacker can obtain a list of smart devices by knowing a valid username. An  unauthenticated attacker can infer the existence of usernames in the system by querying an API. An unauthenticated attacker can get users&amp;#39; emails by knowing usernames. A password reset email will be sent in response to this unsolicited request. An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner&amp;#39;s username.  An attacker can change registered email addresses of other users and take over arbitrary accounts. Unauthenticated attackers can obtain restricted information about a user&amp;#39;s smart device collections (i.e., &amp;#34;rooms&amp;#34;). Unauthenticated attackers can obtain restricted information about a user&amp;#39;s smart device collections (i.e., &amp;#34;scenes&amp;#34;). An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., &amp;#34;rooms&amp;#34;). Unauthenticated attackers can query an API endpoint and get device details. Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers). An unauthenticated attacker can obt…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value while adding or editing a plant. An unauthenticated attacker can check the existence of usernames in the system by querying an API. An authenticated attacker can obtain any plant name by knowing the plant ID. An unauthenticated attacker can obtain a user&amp;#39;s plant list by knowing the username. An unauthenticated attacker can obtain a list of smart devices by knowing a valid username. An  unauthenticated attacker can infer the existence of usernames in the system by querying an API. An unauthenticated attacker can get users&amp;#39; emails by knowing usernames. A password reset email will be sent in response to this unsolicited request. An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner&amp;#39;s username.  An attacker can change registered email addresses of other users and take over arbitrary accounts. Unauthenticated attackers can obtain restricted information about a user&amp;#39;s smart device collections (i.e., &amp;#34;rooms&amp;#34;). Unauthenticated attackers can obtain restricted information about a user&amp;#39;s smart device collections (i.e., &amp;#34;scenes&amp;#34;). An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., &amp;#34;rooms&amp;#34;). Unauthenticated attackers can query an API endpoint and get device details. Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers). An unauthenticated attacker can obt…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-105-04</guid>
    </item>
  </channel>
</rss>
