<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 12:29:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-325821</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-325821</link>
      <description>EUVD-2026-325821</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-325821</guid>
    </item>
    <item>
      <title>fkie_cve-2026-11764</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-11764</link>
      <description>&lt;p&gt;When creating an export of all reusable media, the secrets of connected 
gift cards were included in the export even if the user creating the 
export does not have permission to view gift cards. This is inconsistent
 with the UI and API where only the first letters of the gift card 
secret are shown. Therefore, it allows circumventing a permission 
boundary.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When creating an export of all reusable media, the secrets of connected 
gift cards were included in the export even if the user creating the 
export does not have permission to view gift cards. This is inconsistent
 with the UI and API where only the first letters of the gift card 
secret are shown. Therefore, it allows circumventing a permission 
boundary.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-11764</guid>
    </item>
    <item>
      <title>GHSA-m6hc-99rm-c9wc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m6hc-99rm-c9wc</link>
      <description>&lt;p&gt;When creating an export of all reusable media, the secrets of connected 
gift cards were included in the export even if the user creating the 
export does not have permission to view gift cards. This is inconsistent
 with the UI and API where only the first letters of the gift card 
secret are shown. Therefore, it allows circumventing a permission 
boundary.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When creating an export of all reusable media, the secrets of connected 
gift cards were included in the export even if the user creating the 
export does not have permission to view gift cards. This is inconsistent
 with the UI and API where only the first letters of the gift card 
secret are shown. Therefore, it allows circumventing a permission 
boundary.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m6hc-99rm-c9wc</guid>
    </item>
  </channel>
</rss>
