<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from cvelistv5</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:45:18 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-23481 — Out-of-Bound Read in xrdp</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-23481</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; neutrinolabs xrdp&lt;/p&gt;
&lt;p&gt;xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp &amp;lt; v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; neutrinolabs xrdp&lt;/p&gt;
&lt;p&gt;xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp &amp;lt; v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-23481</guid>
      <pubDate>Fri, 09 Dec 2022 17:50:24 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2022-23482 — Out-of-Bound Read in xrdp</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-23482</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; neutrinolabs xrdp&lt;/p&gt;
&lt;p&gt;xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp &amp;lt; v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; neutrinolabs xrdp&lt;/p&gt;
&lt;p&gt;xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp &amp;lt; v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-23482</guid>
      <pubDate>Fri, 09 Dec 2022 17:50:39 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2023-20057</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-20057</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Cisco Email Security Appliance (ESA)&lt;/p&gt;
&lt;p&gt;A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.&#13;
&#13; This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a particular way. A successful exploit could allow the attacker to bypass the URL reputation filters that are configured for an affected device, which could allow malicious URLs to pass through the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Cisco Email Security Appliance (ESA)&lt;/p&gt;
&lt;p&gt;A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.&#13;
&#13; This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a particular way. A successful exploit could allow the attacker to bypass the URL reputation filters that are configured for an affected device, which could allow malicious URLs to pass through the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-20057</guid>
      <pubDate>Thu, 19 Jan 2023 01:32:32 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2023-23608 — spotipy Path traversal vulnerability that may lead to type confusion in URI handling code</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-23608</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; spotipy-dev spotipy&lt;/p&gt;
&lt;p&gt;Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is passed to the library, the library can be tricked into performing an operation on a different API endpoint than intended. The code Spotipy uses to parse URIs and URLs allows an attacker to insert arbitrary characters into the path that is used for API requests. Because it is possible to include &amp;#34;..&amp;#34;, an attacker can redirect for example a track lookup via spotifyApi.track() to an arbitrary API endpoint like playlists, but this is possible for other endpoints as well. The impact of this vulnerability depends heavily on what operations a client application performs when it handles a URI from a user and how it uses the responses it receives from the API. This issue is patched in version 2.22.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; spotipy-dev spotipy&lt;/p&gt;
&lt;p&gt;Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is passed to the library, the library can be tricked into performing an operation on a different API endpoint than intended. The code Spotipy uses to parse URIs and URLs allows an attacker to insert arbitrary characters into the path that is used for API requests. Because it is possible to include &amp;#34;..&amp;#34;, an attacker can redirect for example a track lookup via spotifyApi.track() to an arbitrary API endpoint like playlists, but this is possible for other endpoints as well. The impact of this vulnerability depends heavily on what operations a client application performs when it handles a URI from a user and how it uses the responses it receives from the API. This issue is patched in version 2.22.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-23608</guid>
      <pubDate>Tue, 24 Jan 2023 02:39:32 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2023-31007 — Apache Pulsar: Broker does not always disconnect client when authentication data expires</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-31007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Pulsar&lt;/p&gt;
&lt;p&gt;Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authentication data expires if the client connected through the Pulsar Proxy when the broker is configured with authenticateOriginalAuthData=false or if a client connects directly to a broker with a specially crafted connect command when the broker is configured with authenticateOriginalAuthData=false.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Pulsar: through 2.9.4, from 2.10.0 through 2.10.3, 2.11.0.&lt;/p&gt;
&lt;p&gt;2.9 Pulsar Broker users should upgrade to at least 2.9.5.
2.10 Pulsar Broker users should upgrade to at least 2.10.4.
2.11 Pulsar Broker users should upgrade to at least 2.11.1.
3.0 Pulsar Broker users are unaffected.
Any users running the Pulsar Broker for 2.8.* and earlier should upgrade to one of the above patched versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Pulsar&lt;/p&gt;
&lt;p&gt;Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authentication data expires if the client connected through the Pulsar Proxy when the broker is configured with authenticateOriginalAuthData=false or if a client connects directly to a broker with a specially crafted connect command when the broker is configured with authenticateOriginalAuthData=false.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Pulsar: through 2.9.4, from 2.10.0 through 2.10.3, 2.11.0.&lt;/p&gt;
&lt;p&gt;2.9 Pulsar Broker users should upgrade to at least 2.9.5.
2.10 Pulsar Broker users should upgrade to at least 2.10.4.
2.11 Pulsar Broker users should upgrade to at least 2.11.1.
3.0 Pulsar Broker users are unaffected.
Any users running the Pulsar Broker for 2.8.* and earlier should upgrade to one of the above patched versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-31007</guid>
      <pubDate>Wed, 12 Jul 2023 09:07:03 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2023-33182 — Nextcloud Contacts photos only sanitized if mime type is all lower case</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-33182</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nextcloud security-advisories&lt;/p&gt;
&lt;p&gt;Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can&amp;#39;t render. Due to this constellation the missing sanitization does not seem to be exploitable. It is recommended that the Contacts app is upgraded to 5.0.3 or 4.2.4&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nextcloud security-advisories&lt;/p&gt;
&lt;p&gt;Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can&amp;#39;t render. Due to this constellation the missing sanitization does not seem to be exploitable. It is recommended that the Contacts app is upgraded to 5.0.3 or 4.2.4&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-33182</guid>
      <pubDate>Tue, 30 May 2023 04:58:07 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2024-22213 — Cross-site Scripting when sending HTML as a comment in the Nextcloud Deck app</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-22213</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nextcloud security-advisories&lt;/p&gt;
&lt;p&gt;Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; nextcloud security-advisories&lt;/p&gt;
&lt;p&gt;Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is upgraded to version 1.9.5 or 1.11.2. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-22213</guid>
      <pubDate>Thu, 18 Jan 2024 19:11:40 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2024-27088 — es5-ext Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-27088</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; medikoo es5-ext&lt;/p&gt;
&lt;p&gt;es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; medikoo es5-ext&lt;/p&gt;
&lt;p&gt;es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-27088</guid>
      <pubDate>Mon, 26 Feb 2024 16:50:05 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2024-32037 — GeoNetwork vulnerable to search end-point information disclosure in response headers</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-32037</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; geonetwork core-geonetwork&lt;/p&gt;
&lt;p&gt;GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; geonetwork core-geonetwork&lt;/p&gt;
&lt;p&gt;GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-32037</guid>
      <pubDate>Tue, 11 Feb 2025 21:50:29 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2024-3570 — Stored XSS leading to Admin Account Takeover in mintplex-labs/anything-llm</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-3570</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; mintplex-labs/anything-llm&lt;/p&gt;
&lt;p&gt;A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers to execute arbitrary JavaScript in the context of a user&amp;#39;s session. By manipulating the ChatBot responses, an attacker can inject malicious scripts to perform actions on behalf of the user, such as creating a new admin account or changing the user&amp;#39;s password, leading to a complete takeover of the AnythingLLM application. The vulnerability stems from the improper sanitization of user and ChatBot input, specifically through the use of `dangerouslySetInnerHTML`. Successful exploitation requires convincing an admin to add a malicious LocalAI ChatBot to their AnythingLLM instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; mintplex-labs/anything-llm&lt;/p&gt;
&lt;p&gt;A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers to execute arbitrary JavaScript in the context of a user&amp;#39;s session. By manipulating the ChatBot responses, an attacker can inject malicious scripts to perform actions on behalf of the user, such as creating a new admin account or changing the user&amp;#39;s password, leading to a complete takeover of the AnythingLLM application. The vulnerability stems from the improper sanitization of user and ChatBot input, specifically through the use of `dangerouslySetInnerHTML`. Successful exploitation requires convincing an admin to add a malicious LocalAI ChatBot to their AnythingLLM instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-3570</guid>
      <pubDate>Wed, 10 Apr 2024 17:08:15 +0000</pubDate>
    </item>
  </channel>
</rss>
