<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from fkie_nvd</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 11:36:42 +0000</lastBuildDate>
    <item>
      <title>fkie_cve-2026-84224</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84224</link>
      <description>&lt;p&gt;The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84224</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:10 +0000</pubDate>
    </item>
    <item>
      <title>fkie_cve-2026-84220</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84220</link>
      <description>&lt;p&gt;The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84220</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:09 +0000</pubDate>
    </item>
    <item>
      <title>fkie_cve-2026-78022</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78022</link>
      <description>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely (&amp;#39;Failing Open&amp;#39;) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely (&amp;#39;Failing Open&amp;#39;) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-78022</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:09 +0000</pubDate>
    </item>
    <item>
      <title>fkie_cve-2026-78021</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78021</link>
      <description>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information exposure.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information exposure.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-78021</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:09 +0000</pubDate>
    </item>
    <item>
      <title>fkie_cve-2026-78020</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78020</link>
      <description>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-78020</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:09 +0000</pubDate>
    </item>
    <item>
      <title>fkie_cve-2026-78019</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78019</link>
      <description>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Filesystem access for attacker, and Remote execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Filesystem access for attacker, and Remote execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-78019</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:09 +0000</pubDate>
    </item>
    <item>
      <title>fkie_cve-2026-78018</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78018</link>
      <description>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-78018</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:09 +0000</pubDate>
    </item>
    <item>
      <title>fkie_cve-2026-78017</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78017</link>
      <description>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-78017</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:08 +0000</pubDate>
    </item>
    <item>
      <title>fkie_cve-2026-78016</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78016</link>
      <description>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Validation of Specified Type of Input vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure and Information tampering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Validation of Specified Type of Input vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure and Information tampering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-78016</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:08 +0000</pubDate>
    </item>
    <item>
      <title>fkie_cve-2026-78015</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78015</link>
      <description>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Less Trusted Source vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Less Trusted Source vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-78015</guid>
      <pubDate>Fri, 09 Oct 2026 09:17:08 +0000</pubDate>
    </item>
  </channel>
</rss>
