<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/nvd/10</id>
  <title>Most recent entries from nvd</title>
  <updated>2026-10-02T12:27:21.194247+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-50356</id>
    <title>CVE-2024-50356 — Press has a potential 2FA bypass</title>
    <updated>2024-11-01T13:51:00.632000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> frappe press</p>
<p>Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn't be able to login by bypassing the 2FA. Only users who have enabled 2FA are affected. Commit ba0007c28ac814260f836849bc07d29beea7deb6 patches this bug.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-50356"/>
    <published>2024-10-31T18:02:42.440000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-11173</id>
    <title>CVE-2025-11173 — Reauth for enabling 2FA can be bypassed by submitting a form</title>
    <updated>2026-02-03T21:08:02.478000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Wikimedia Foundation OATHAuth</p>
<p>Vulnerability in Wikimedia Foundation OATHAuth. This vulnerability is associated with program files src/Special/OATHManage.Php.</p>
<p>This issue affects OATHAuth: from * before 1.39.14, 1.43.4, 1.44.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-11173"/>
    <published>2026-02-03T00:27:45.487000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-1680</id>
    <title>CVE-2025-1680</title>
    <updated>2025-10-23T14:35:30.379000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Moxa TN-4500A Series, Moxa TN-5500A Series, Moxa TN-G4500 Series, Moxa TN-G6500 Series</p>
<p>An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service. This vulnerability is classified as Host Header Injection, where invalid Host headers can manipulate to redirect users, forge links, or phishing attacks. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of confidentiality, integrity, and availability within any subsequent systems.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-1680"/>
    <published>2025-10-23T13:56:39.744000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-26862</id>
    <title>CVE-2025-26862 — PingFederate unexpected browser flow initiation in redirectless mode</title>
    <updated>2025-10-27T14:48:11.544000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ping Identity PingFederate</p>
<p>Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-26862"/>
    <published>2025-10-27T14:39:41.284000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-32696</id>
    <title>CVE-2025-32696 — "reupload-own" restriction can be bypassed by reverting file</title>
    <updated>2025-11-03T19:53:33.707000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Wikimedia Foundation MediaWiki</p>
<p>Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php.</p>
<p>This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-32696"/>
    <published>2025-04-10T18:28:48.161000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-32697</id>
    <title>CVE-2025-32697 — Cascading protection is not preventing file reversions</title>
    <updated>2025-04-10T19:05:48.098000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Wikimedia Foundation MediaWiki</p>
<p>Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, includes/Permissions/RestrictionStore.Php.</p>
<p>This issue affects MediaWiki: before 1.42.6, 1.43.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-32697"/>
    <published>2025-04-10T18:29:17.482000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-3469</id>
    <title>CVE-2025-3469 — i18n XSS vulnerability in HTMLMultiSelectField when sections are used</title>
    <updated>2025-11-03T19:53:59.985000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Wikimedia Foundation MediaWiki</p>
<p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLMultiSelectField.Php.</p>
<p>This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-3469"/>
    <published>2025-04-10T18:28:13.370000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-49823</id>
    <title>CVE-2025-49823 — Conda Constructor Command Injection via Unsanitized User Input (Low)</title>
    <updated>2025-06-17T15:52:25.295000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> conda constructor</p>
<p>(conda) Constructor is a tool which allows constructing an installer for a collection of conda packages. Prior to version 3.11.3, shell installer scripts process the installation prefix (user_prefix) using an eval statement, which executes unsanitized user input as shell code. Although the script runs with user privileges (not root), an attacker could exploit this by injecting arbitrary commands through a malicious path during installation. Exploitation requires explicit user action. This issue has been patched in version 3.11.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-49823"/>
    <published>2025-06-17T02:21:17.496000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-61635</id>
    <title>CVE-2025-61635 — Add rate limiting to ApiFancyCaptchaReload</title>
    <updated>2026-02-03T21:13:41.151000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Wikimedia Foundation ConfirmEdit</p>
<p>Vulnerability in Wikimedia Foundation ConfirmEdit. This vulnerability is associated with program files includes/FancyCaptcha/ApiFancyCaptchaReload.Php.</p>
<p>This issue affects ConfirmEdit: *.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-61635"/>
    <published>2026-02-02T23:26:14.537000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-61644</id>
    <title>CVE-2025-61644 — i18n XSS through Special:Watchlist</title>
    <updated>2026-02-03T21:03:59.441000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Wikimedia Foundation MediaWiki</p>
<p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Rcfilters/ui/WatchlistTopSectionWidget.Js.</p>
<p>This issue affects MediaWiki: from * before &gt; fb856ce9cf121e046305116852cca4899ecb48ca.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-61644"/>
    <published>2026-02-02T23:57:17.522000+00:00</published>
  </entry>
</feed>
