<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from github</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:09:54 +0000</lastBuildDate>
    <item>
      <title>GHSA-v78q-44mm-wf7q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v78q-44mm-wf7q</link>
      <description>&lt;p&gt;A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v78q-44mm-wf7q</guid>
      <pubDate>Fri, 02 Oct 2026 03:31:10 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-r4mc-xrrj-f33f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r4mc-xrrj-f33f</link>
      <description>&lt;p&gt;A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r4mc-xrrj-f33f</guid>
      <pubDate>Fri, 02 Oct 2026 03:31:10 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-qc9g-wj38-hfvp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qc9g-wj38-hfvp</link>
      <description>&lt;p&gt;Transmission of a sensitive key in the URL
over an unencrypted HTTP connection.  The
request is sent over HTTP rather than HTTPS, meaning the key is transmitted in
plaintext across the network. An attacker with the ability to monitor network
traffic could intercept the request and obtain the key&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Transmission of a sensitive key in the URL
over an unencrypted HTTP connection.  The
request is sent over HTTP rather than HTTPS, meaning the key is transmitted in
plaintext across the network. An attacker with the ability to monitor network
traffic could intercept the request and obtain the key&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qc9g-wj38-hfvp</guid>
      <pubDate>Fri, 02 Oct 2026 03:31:10 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-mwfx-8rgq-rc8f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mwfx-8rgq-rc8f</link>
      <description>&lt;p&gt;An API key is
hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the key.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An API key is
hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the key.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mwfx-8rgq-rc8f</guid>
      <pubDate>Fri, 02 Oct 2026 03:31:10 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-m6q3-w82g-46vw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m6q3-w82g-46vw</link>
      <description>&lt;p&gt;A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m6q3-w82g-46vw</guid>
      <pubDate>Fri, 02 Oct 2026 03:31:10 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-hrq7-vgh7-p534</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hrq7-vgh7-p534</link>
      <description>&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hrq7-vgh7-p534</guid>
      <pubDate>Mon, 20 Jul 2026 12:33:08 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-crm9-6p8f-6cx9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-crm9-6p8f-6cx9</link>
      <description>&lt;p&gt;Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-crm9-6p8f-6cx9</guid>
      <pubDate>Fri, 02 Oct 2026 03:31:10 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-4vh9-ff7c-v4f2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4vh9-ff7c-v4f2</link>
      <description>&lt;p&gt;A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4vh9-ff7c-v4f2</guid>
      <pubDate>Fri, 02 Oct 2026 03:31:10 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-48q5-8whv-r6xj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-48q5-8whv-r6xj</link>
      <description>&lt;p&gt;A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-48q5-8whv-r6xj</guid>
      <pubDate>Fri, 02 Oct 2026 03:31:10 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-3q99-x36r-rchh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3q99-x36r-rchh</link>
      <description>&lt;p&gt;Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3q99-x36r-rchh</guid>
      <pubDate>Fri, 02 Oct 2026 03:31:10 +0000</pubDate>
    </item>
  </channel>
</rss>
