<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:48:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-274088</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274088</link>
      <description>EUVD-2026-274088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274088</guid>
    </item>
    <item>
      <title>fkie_cve-2026-28360</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28360</link>
      <description>&lt;p&gt;NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-28360</guid>
    </item>
    <item>
      <title>GHSA-mpp2-x7wv-38hv — NocoDB has Plaintext Storage of Shared View Passwords</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mpp2-x7wv-38hv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nocodb&lt;/p&gt;
&lt;p&gt;### Summary
Shared view passwords were stored in plaintext in the database and compared using direct string equality.&lt;/p&gt;
&lt;p&gt;### Details
The `password` column in `nc_views` stored unhashed passwords. Verification used `!==` comparison across `public-datas.service.ts`, `public-metas.service.ts`, and `calendar-datas.service.ts`.&lt;/p&gt;
&lt;p&gt;### Impact
If the database is compromised, shared view passwords are immediately readable. Risk is limited to password reuse scenarios.&lt;/p&gt;
&lt;p&gt;### Credit
This issue was reported by [@Tulgaaaaaaaa](https://github.com/Tulgaaaaaaaa).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nocodb&lt;/p&gt;
&lt;p&gt;### Summary
Shared view passwords were stored in plaintext in the database and compared using direct string equality.&lt;/p&gt;
&lt;p&gt;### Details
The `password` column in `nc_views` stored unhashed passwords. Verification used `!==` comparison across `public-datas.service.ts`, `public-metas.service.ts`, and `calendar-datas.service.ts`.&lt;/p&gt;
&lt;p&gt;### Impact
If the database is compromised, shared view passwords are immediately readable. Risk is limited to password reuse scenarios.&lt;/p&gt;
&lt;p&gt;### Credit
This issue was reported by [@Tulgaaaaaaaa](https://github.com/Tulgaaaaaaaa).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mpp2-x7wv-38hv</guid>
    </item>
  </channel>
</rss>
