<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://127.0.0.1:10001/cna-root/ENISA/recent</id>
  <title>Most recent vulnerabilities from the ENISA CNA root</title>
  <updated>2026-10-03T16:09:11.939059+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>info@circl.lu</email>
  </author>
  <link href="https://127.0.0.1:10001" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Latest vulnerabilities published by the CNAs operating under the ENISA root of the CVE Program.</subtitle>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104914</id>
    <title>CVE-2026-104914 (CIRCL)</title>
    <updated>2026-10-02T16:09:40.333000+00:00</updated>
    <content>MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104914"/>
    <summary>MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View</summary>
    <published>2026-10-02T16:09:40.333000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104912</id>
    <title>CVE-2026-104912 (CIRCL)</title>
    <updated>2026-10-02T16:04:50.580000+00:00</updated>
    <content>MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104912"/>
    <summary>MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data</summary>
    <published>2026-10-02T16:04:50.580000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104910</id>
    <title>CVE-2026-104910 (CIRCL)</title>
    <updated>2026-10-02T16:01:32.781000+00:00</updated>
    <content>MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104910"/>
    <summary>MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization</summary>
    <published>2026-10-02T16:01:32.781000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104908</id>
    <title>CVE-2026-104908 (CIRCL)</title>
    <updated>2026-10-02T15:56:13.969000+00:00</updated>
    <content>MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104908"/>
    <summary>MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging</summary>
    <published>2026-10-02T15:56:13.969000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104907</id>
    <title>CVE-2026-104907 (CIRCL)</title>
    <updated>2026-10-02T15:51:34.565000+00:00</updated>
    <content>MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104907"/>
    <summary>MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler</summary>
    <published>2026-10-02T15:51:34.565000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104906</id>
    <title>CVE-2026-104906 (CIRCL)</title>
    <updated>2026-10-02T15:49:32.948000+00:00</updated>
    <content>MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104906"/>
    <summary>MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output</summary>
    <published>2026-10-02T15:49:32.948000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104901</id>
    <title>CVE-2026-104901 (CIRCL)</title>
    <updated>2026-10-02T15:21:53.492000+00:00</updated>
    <content>MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104901"/>
    <summary>MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server</summary>
    <published>2026-10-02T15:21:53.492000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104900</id>
    <title>CVE-2026-104900 (CIRCL)</title>
    <updated>2026-10-02T15:16:27.485000+00:00</updated>
    <content>MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104900"/>
    <summary>MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index</summary>
    <published>2026-10-02T15:16:27.485000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-91784</id>
    <title>CVE-2026-91784 (CERT-PL)</title>
    <updated>2026-10-02T08:38:42.744000+00:00</updated>
    <content>Argument Injection leading to arbitrary process termination in gotop</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-91784"/>
    <summary>Argument Injection leading to arbitrary process termination in gotop</summary>
    <published>2026-10-02T08:38:42.744000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-103858</id>
    <title>CVE-2026-103858 (CIRCL)</title>
    <updated>2026-10-01T11:31:32.840000+00:00</updated>
    <content>MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-103858"/>
    <summary>MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions</summary>
    <published>2026-10-01T11:31:32.840000+00:00</published>
  </entry>
</feed>
