<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/nvd/10</id>
  <title>Most recent entries from nvd</title>
  <updated>2026-10-03T00:40:30.050236+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-84411</id>
    <title>CVE-2026-84411 — MikroTik RouterOS Integer Underflow</title>
    <updated>2026-10-02T22:09:48.298000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> MikroTik RouterOS</p>
<p>The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-84411"/>
    <published>2026-10-02T22:09:48.298000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105051</id>
    <title>CVE-2026-105051</title>
    <updated>2026-10-02T22:59:56.650000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Irdeto Denuvo Anti-Tamper</p>
<p>Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105051"/>
    <published>2026-10-02T22:59:56.650000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105050</id>
    <title>CVE-2026-105050</title>
    <updated>2026-10-02T22:37:54.551000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PeaZip</p>
<p>PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105050"/>
    <published>2026-10-02T22:37:54.551000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105049</id>
    <title>CVE-2026-105049</title>
    <updated>2026-10-02T22:14:36.181000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Zilliz Attu</p>
<p>Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105049"/>
    <published>2026-10-02T22:14:36.181000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105048</id>
    <title>CVE-2026-105048</title>
    <updated>2026-10-02T22:08:31.771000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Zilliz Attu</p>
<p>The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105048"/>
    <published>2026-10-02T22:08:31.771000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97363</id>
    <title>CVE-2026-97363 — Monta monta.app Improper Restriction of Excessive Authentication Attempts</title>
    <updated>2026-10-02T21:32:30.615000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> monta.app</p>
<p>The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97363"/>
    <published>2026-10-02T21:32:30.615000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97212</id>
    <title>CVE-2026-97212 — Monta monta.app Insufficient Session Expiration</title>
    <updated>2026-10-02T21:30:37.104000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> monta.app</p>
<p>The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97212"/>
    <published>2026-10-02T21:30:37.104000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-95102</id>
    <title>CVE-2026-95102 — Monta monta.app Missing Authentication for Critical Function</title>
    <updated>2026-10-02T21:34:37.182000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> monta.app</p>
<p>WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-95102"/>
    <published>2026-10-02T21:34:37.182000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-94594</id>
    <title>CVE-2026-94594 — Armatura LLC Armatura One Insertion of Sensitive Information into Log File</title>
    <updated>2026-10-02T21:48:14.765000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Armatura LLC Armatura One, Armatura LLC Armatura One (USA)</p>
<p>Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-94594"/>
    <published>2026-10-02T21:48:14.765000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-94593</id>
    <title>CVE-2026-94593 — Armatura LLC Armatura One Insertion of Sensitive Information into Log File</title>
    <updated>2026-10-02T21:51:00.902000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Armatura LLC Armatura One, Armatura LLC Armatura One (USA)</p>
<p>Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-94593"/>
    <published>2026-10-02T21:51:00.902000+00:00</published>
  </entry>
</feed>
