<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/cvelistv5/10</id>
  <title>Most recent entries from cvelistv5</title>
  <updated>2026-10-02T12:11:50.272452+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2022-23481</id>
    <title>CVE-2022-23481 — Out-of-Bound Read in xrdp</title>
    <updated>2025-04-23T16:29:49.845000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> neutrinolabs xrdp</p>
<p>xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp &lt; v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2022-23481"/>
    <published>2022-12-09T17:50:24.280000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2022-23482</id>
    <title>CVE-2022-23482 — Out-of-Bound Read in xrdp</title>
    <updated>2025-04-23T16:29:43.350000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> neutrinolabs xrdp</p>
<p>xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp &lt; v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2022-23482"/>
    <published>2022-12-09T17:50:39.075000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2023-20057</id>
    <title>CVE-2023-20057</title>
    <updated>2024-08-02T08:57:35.557000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Cisco Email Security Appliance (ESA)</p>
<p>A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.

 This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a particular way. A successful exploit could allow the attacker to bypass the URL reputation filters that are configured for an affected device, which could allow malicious URLs to pass through the device.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2023-20057"/>
    <published>2023-01-19T01:32:32.802000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2023-23608</id>
    <title>CVE-2023-23608 — spotipy Path traversal vulnerability that may lead to type confusion in URI handling code</title>
    <updated>2025-03-10T21:20:38.544000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> spotipy-dev spotipy</p>
<p>Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is passed to the library, the library can be tricked into performing an operation on a different API endpoint than intended. The code Spotipy uses to parse URIs and URLs allows an attacker to insert arbitrary characters into the path that is used for API requests. Because it is possible to include "..", an attacker can redirect for example a track lookup via spotifyApi.track() to an arbitrary API endpoint like playlists, but this is possible for other endpoints as well. The impact of this vulnerability depends heavily on what operations a client application performs when it handles a URI from a user and how it uses the responses it receives from the API. This issue is patched in version 2.22.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2023-23608"/>
    <published>2023-01-24T02:39:32.471000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2023-31007</id>
    <title>CVE-2023-31007 — Apache Pulsar: Broker does not always disconnect client when authentication data expires</title>
    <updated>2024-10-08T13:35:57.720000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Apache Software Foundation Apache Pulsar</p>
<p>Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authentication data expires if the client connected through the Pulsar Proxy when the broker is configured with authenticateOriginalAuthData=false or if a client connects directly to a broker with a specially crafted connect command when the broker is configured with authenticateOriginalAuthData=false.</p>
<p>This issue affects Apache Pulsar: through 2.9.4, from 2.10.0 through 2.10.3, 2.11.0.</p>
<p>2.9 Pulsar Broker users should upgrade to at least 2.9.5.
2.10 Pulsar Broker users should upgrade to at least 2.10.4.
2.11 Pulsar Broker users should upgrade to at least 2.11.1.
3.0 Pulsar Broker users are unaffected.
Any users running the Pulsar Broker for 2.8.* and earlier should upgrade to one of the above patched versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2023-31007"/>
    <published>2023-07-12T09:07:03.227000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2023-33182</id>
    <title>CVE-2023-33182 — Nextcloud Contacts photos only sanitized if mime type is all lower case</title>
    <updated>2025-01-10T19:59:11.557000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> nextcloud security-advisories</p>
<p>Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to be exploitable. It is recommended that the Contacts app is upgraded to 5.0.3 or 4.2.4</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2023-33182"/>
    <published>2023-05-30T04:58:07.669000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-22213</id>
    <title>CVE-2024-22213 — Cross-site Scripting when sending HTML as a comment in the Nextcloud Deck app</title>
    <updated>2024-11-13T19:21:11.400000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> nextcloud security-advisories</p>
<p>Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-22213"/>
    <published>2024-01-18T19:11:40.584000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-27088</id>
    <title>CVE-2024-27088 — es5-ext Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`</title>
    <updated>2024-08-09T18:21:21.894000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> medikoo es5-ext</p>
<p>es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-27088"/>
    <published>2024-02-26T16:50:05.714000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-32037</id>
    <title>CVE-2024-32037 — GeoNetwork vulnerable to search end-point information disclosure in response headers</title>
    <updated>2025-02-12T15:37:46.364000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> geonetwork core-geonetwork</p>
<p>GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-32037"/>
    <published>2025-02-11T21:50:29.138000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-3570</id>
    <title>CVE-2024-3570 — Stored XSS leading to Admin Account Takeover in mintplex-labs/anything-llm</title>
    <updated>2024-08-01T20:12:07.798000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> mintplex-labs/anything-llm</p>
<p>A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers to execute arbitrary JavaScript in the context of a user's session. By manipulating the ChatBot responses, an attacker can inject malicious scripts to perform actions on behalf of the user, such as creating a new admin account or changing the user's password, leading to a complete takeover of the AnythingLLM application. The vulnerability stems from the improper sanitization of user and ChatBot input, specifically through the use of `dangerouslySetInnerHTML`. Successful exploitation requires convincing an admin to add a malicious LocalAI ChatBot to their AnythingLLM instance.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-3570"/>
    <published>2024-04-10T17:08:15.109000+00:00</published>
  </entry>
</feed>
