<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/cvelistv5/10</id>
  <title>Most recent entries from cvelistv5</title>
  <updated>2026-10-02T11:09:11.728695+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97360</id>
    <title>CVE-2026-97360 — HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine</title>
    <updated>2026-09-24T15:00:30.695000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> rejetto hfs2</p>
<p>HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97360"/>
    <published>2026-09-24T13:32:32.185000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97359</id>
    <title>CVE-2026-97359 — HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection</title>
    <updated>2026-09-29T02:44:54.569000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> rejetto hfs2</p>
<p>HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97359"/>
    <published>2026-09-24T13:28:18.818000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97163</id>
    <title>CVE-2026-97163 — Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29</title>
    <updated>2026-09-27T04:47:20.414000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> lomart.fr UP plugin for Joomla</p>
<p>Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97163"/>
    <published>2026-09-26T14:33:44.748000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-96587</id>
    <title>CVE-2026-96587 — Use of Hard-coded Credentials in Viidure Dashcam Android Application</title>
    <updated>2026-09-29T21:02:00.222000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Viidure Dashcam Android Application</p>
<p>The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-96587"/>
    <published>2026-09-29T20:42:38.270000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-96349</id>
    <title>CVE-2026-96349 — WordPress SiteSkite plugin &lt;= 2.1.8 - Remote Code Execution (RCE) vulnerability</title>
    <updated>2026-09-30T13:27:06.769000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> SiteSkite</p>
<p>Unauthenticated Remote Code Execution (RCE) in SiteSkite &lt;= 2.1.8 versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-96349"/>
    <published>2026-09-30T12:27:24.923000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-96257</id>
    <title>CVE-2026-96257 — Fast FAC1203R Gigabit Edition Device Discovery Service copy_msg_element stack-based overflow</title>
    <updated>2026-09-23T14:07:16.689000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Fast FAC1203R Gigabit Edition</p>
<p>A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-96257"/>
    <published>2026-09-23T03:00:10.174000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-9508</id>
    <title>CVE-2026-9508 — Incorrect Permission Assignment for Critical Resource vulnerability in Suprema's BioStar</title>
    <updated>2026-05-29T13:33:31.937000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Suprema BioStar 2 (server)</p>
<p>Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an attacker with network access to directly download backup ZIP files via ‘http(s)://[server]/download/…’ without requiring authentication. This exposes highly sensitive information that can lead to server impersonation, unauthorized access to databases, and lateral movement.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-9508"/>
    <published>2026-05-29T12:09:02.026000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-94493</id>
    <title>CVE-2026-94493 — Gigatech PDV5701 WebSocket Service index.html missing authentication</title>
    <updated>2026-09-24T22:55:54.918000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Gigatech PDV5701</p>
<p>A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-94493"/>
    <published>2026-09-22T01:00:18.544000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-94097</id>
    <title>CVE-2026-94097 — Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection</title>
    <updated>2026-09-24T12:43:07.627000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Netcore NBR200V2</p>
<p>A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-94097"/>
    <published>2026-09-20T23:45:10.912000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-94089</id>
    <title>CVE-2026-94089 — D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow</title>
    <updated>2026-09-22T15:42:13.561000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> D-Link DIR-868L</p>
<p>A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-94089"/>
    <published>2026-09-20T20:45:10.159000+00:00</published>
  </entry>
</feed>
