<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent vulnerabilities from the ENISA CNA root</title>
    <link>https://127.0.0.1:10001</link>
    <description>Latest vulnerabilities published by the CNAs operating under the ENISA root of the CVE Program.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:09:12 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-104914 (CIRCL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104914</link>
      <description>MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View</description>
      <content:encoded>MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104914</guid>
      <pubDate>Fri, 02 Oct 2026 16:09:40 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104912 (CIRCL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104912</link>
      <description>MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data</description>
      <content:encoded>MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104912</guid>
      <pubDate>Fri, 02 Oct 2026 16:04:50 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104910 (CIRCL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104910</link>
      <description>MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization</description>
      <content:encoded>MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104910</guid>
      <pubDate>Fri, 02 Oct 2026 16:01:32 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104908 (CIRCL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104908</link>
      <description>MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging</description>
      <content:encoded>MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104908</guid>
      <pubDate>Fri, 02 Oct 2026 15:56:13 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104907 (CIRCL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104907</link>
      <description>MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler</description>
      <content:encoded>MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104907</guid>
      <pubDate>Fri, 02 Oct 2026 15:51:34 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104906 (CIRCL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104906</link>
      <description>MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output</description>
      <content:encoded>MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104906</guid>
      <pubDate>Fri, 02 Oct 2026 15:49:32 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104901 (CIRCL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104901</link>
      <description>MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server</description>
      <content:encoded>MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104901</guid>
      <pubDate>Fri, 02 Oct 2026 15:21:53 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104900 (CIRCL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104900</link>
      <description>MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index</description>
      <content:encoded>MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104900</guid>
      <pubDate>Fri, 02 Oct 2026 15:16:27 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-91784 (CERT-PL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-91784</link>
      <description>Argument Injection leading to arbitrary process termination in gotop</description>
      <content:encoded>Argument Injection leading to arbitrary process termination in gotop</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-91784</guid>
      <pubDate>Fri, 02 Oct 2026 08:38:42 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103858 (CIRCL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103858</link>
      <description>MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions</description>
      <content:encoded>MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103858</guid>
      <pubDate>Thu, 01 Oct 2026 11:31:32 +0000</pubDate>
    </item>
  </channel>
</rss>
