<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/categories/metier-donnees.xml</id>
  <title>Exploit Radar: ERP, business applications and databases</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities in the “ERP, business applications and databases” category (indicative classification).</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/categories/metier-donnees.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/produits/metier-donnees/"/>
  <updated>2026-08-26T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-1068/</id>
    <title>CVE-2019-1068 — Microsoft SQL Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-1068/"/>
    <updated>2026-08-26T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Microsoft; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 26, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-72898/</id>
    <title>CVE-2026-72898 — Metabase</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-72898/"/>
    <updated>2026-08-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Metabase; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Active CERT-FR alert. Added to CISA’s catalog of exploited vulnerabilities on August 11, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-46817/</id>
    <title>CVE-2026-46817 — Oracle E-Business Suite</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-46817/"/>
    <updated>2026-07-15T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Oracle; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on July 15, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-12569/</id>
    <title>CVE-2026-12569 — PTC Windchill and FlexPLM</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-12569/"/>
    <updated>2026-06-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from PTC; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 3 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on June 25, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-35273/</id>
    <title>CVE-2026-35273 — Oracle PeopleSoft</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-35273/"/>
    <updated>2026-06-12T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Oracle; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 3 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on June 12, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-7399/</id>
    <title>CVE-2024-7399 — Samsung MagicINFO Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-7399/"/>
    <updated>2026-04-24T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Samsung; if none are available, stop using the product. For cloud services, follow the guidance from Samsung. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on April 24, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-14847/</id>
    <title>CVE-2025-14847 — MongoDB Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-14847/"/>
    <updated>2025-12-29T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from MongoDB; if none are available, stop using the product. For cloud services, follow the guidance from MongoDB. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on December 29, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-58360/</id>
    <title>CVE-2025-58360 — OSGeo GeoServer</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-58360/"/>
    <updated>2025-12-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from OSGeo; if none are available, stop using the product. For cloud services, follow the guidance from OSGeo. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on December 11, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-6205/</id>
    <title>CVE-2025-6205 — Dassault Systèmes DELMIA Apriso</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-6205/"/>
    <updated>2025-10-28T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Dassault Systèmes; if none are available, stop using the product. For cloud services, follow the guidance from Dassault Systèmes. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on October 28, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-6204/</id>
    <title>CVE-2025-6204 — Dassault Systèmes DELMIA Apriso</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-6204/"/>
    <updated>2025-10-28T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Dassault Systèmes; if none are available, stop using the product. For cloud services, follow the guidance from Dassault Systèmes. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on October 28, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-61884/</id>
    <title>CVE-2025-61884 — Oracle E-Business Suite</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-61884/"/>
    <updated>2025-10-20T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Oracle; if none are available, stop using the product. For cloud services, follow the guidance from Oracle. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on October 20, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-61882/</id>
    <title>CVE-2025-61882 — Oracle E-Business Suite</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-61882/"/>
    <updated>2025-10-06T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Oracle; if none are available, stop using the product. For cloud services, follow the guidance from Oracle. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on October 6, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-21311/</id>
    <title>CVE-2021-21311 — Adminer</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-21311/"/>
    <updated>2025-09-29T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Adminer; if none are available, stop using the product. For cloud services, follow the guidance from Adminer. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on September 29, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-5086/</id>
    <title>CVE-2025-5086 — Dassault Systèmes DELMIA Apriso</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-5086/"/>
    <updated>2025-09-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Dassault Systèmes; if none are available, stop using the product. For cloud services, follow the guidance from Dassault Systèmes. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on September 11, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-4632/</id>
    <title>CVE-2025-4632 — Samsung MagicINFO Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-4632/"/>
    <updated>2025-05-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Samsung; if none are available, stop using the product. For cloud services, follow the guidance from Samsung. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on May 22, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-42999/</id>
    <title>CVE-2025-42999 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-42999/"/>
    <updated>2025-05-15T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SAP; if none are available, stop using the product. For cloud services, follow the guidance from SAP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on May 15, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-31324/</id>
    <title>CVE-2025-31324 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-31324/"/>
    <updated>2025-04-29T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SAP; if none are available, stop using the product. For cloud services, follow the guidance from SAP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 29, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2017-12637/</id>
    <title>CVE-2017-12637 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2017-12637/"/>
    <updated>2025-03-19T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SAP; if none are available, stop using the product. For cloud services, follow the guidance from SAP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 19, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-57968/</id>
    <title>CVE-2024-57968 — Advantive VeraCore</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-57968/"/>
    <updated>2025-03-10T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Advantive; if none are available, stop using the product. For cloud services, follow the guidance from Advantive. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 10, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-25181/</id>
    <title>CVE-2025-25181 — Advantive VeraCore</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-25181/"/>
    <updated>2025-03-10T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Advantive; if none are available, stop using the product. For cloud services, follow the guidance from Advantive. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 10, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-43939/</id>
    <title>CVE-2022-43939 — Hitachi Vantara Pentaho Business Analytics (BA) Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-43939/"/>
    <updated>2025-03-03T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Hitachi Vantara; if none are available, stop using the product. For cloud services, follow the guidance from Hitachi Vantara. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 3, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-43769/</id>
    <title>CVE-2022-43769 — Hitachi Vantara Pentaho Business Analytics (BA) Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-43769/"/>
    <updated>2025-03-03T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Hitachi Vantara; if none are available, stop using the product. For cloud services, follow the guidance from Hitachi Vantara. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 3, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-20953/</id>
    <title>CVE-2024-20953 — Oracle Agile PLM</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-20953/"/>
    <updated>2025-02-24T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Oracle; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 24, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-0994/</id>
    <title>CVE-2025-0994 — Trimble Cityworks</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-0994/"/>
    <updated>2025-02-07T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Trimble; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 7, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-45195/</id>
    <title>CVE-2024-45195 — Apache OFBiz</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-45195/"/>
    <updated>2025-02-04T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Apache; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 4, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-48365/</id>
    <title>CVE-2023-48365 — Qlik Sense</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-48365/"/>
    <updated>2025-01-13T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Qlik; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on January 13, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-44207/</id>
    <title>CVE-2021-44207 — Acclaim Systems USAHERDS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-44207/"/>
    <updated>2024-12-23T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Acclaim Systems; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on December 23, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-21287/</id>
    <title>CVE-2024-21287 — Oracle Agile PLM</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-21287/"/>
    <updated>2024-11-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Oracle; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 21, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-41277/</id>
    <title>CVE-2021-41277 — Metabase</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-41277/"/>
    <updated>2024-11-12T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Metabase; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 12, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-27348/</id>
    <title>CVE-2024-27348 — Apache HugeGraph</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-27348/"/>
    <updated>2024-09-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Apache; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on September 18, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-0618/</id>
    <title>CVE-2020-0618 — Microsoft SQL Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-0618/"/>
    <updated>2024-09-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Microsoft; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on September 18, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-38856/</id>
    <title>CVE-2024-38856 — Apache OFBiz</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-38856/"/>
    <updated>2024-08-27T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Apache; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 27, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-32113/</id>
    <title>CVE-2024-32113 — Apache OFBiz</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-32113/"/>
    <updated>2024-08-07T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Apache; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 7, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-36401/</id>
    <title>CVE-2024-36401 — OSGeo GeoServer</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-36401/"/>
    <updated>2024-07-15T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from OSGeo; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 15, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-24816/</id>
    <title>CVE-2022-24816 — OSGeo GeoServer</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-24816/"/>
    <updated>2024-06-26T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from OSGeo; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 26, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-4358/</id>
    <title>CVE-2024-4358 — Progress Telerik Report Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-4358/"/>
    <updated>2024-06-13T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Progress; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 13, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-4978/</id>
    <title>CVE-2024-4978 — Justice AV Solutions (JAVS) JAVS Viewer</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-4978/"/>
    <updated>2024-05-29T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Justice AV Solutions (JAVS); if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on May 29, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-17519/</id>
    <title>CVE-2020-17519 — Apache Flink</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-17519/"/>
    <updated>2024-05-23T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Apache; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on May 23, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-43208/</id>
    <title>CVE-2023-43208 — NextGen Healthcare Mirth Connect</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-43208/"/>
    <updated>2024-05-20T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from NextGen Healthcare; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on May 20, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-27524/</id>
    <title>CVE-2023-27524 — Apache Superset</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-27524/"/>
    <updated>2024-01-08T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Apache; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on January 8, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-41265/</id>
    <title>CVE-2023-41265 — Qlik Sense</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-41265/"/>
    <updated>2023-12-07T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Qlik; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on December 7, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-41266/</id>
    <title>CVE-2023-41266 — Qlik Sense</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-41266/"/>
    <updated>2023-12-07T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Qlik; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on December 7, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-29492/</id>
    <title>CVE-2023-29492 — Novi Survey</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-29492/"/>
    <updated>2023-04-13T00:00:00Z</updated>
    <summary type="text">Apply the security update from Novi Survey. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 13, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-33891/</id>
    <title>CVE-2022-33891 — Apache Spark</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-33891/"/>
    <updated>2023-03-07T00:00:00Z</updated>
    <summary type="text">Apply the security update from Apache. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 7, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-21587/</id>
    <title>CVE-2022-21587 — Oracle E-Business Suite</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-21587/"/>
    <updated>2023-02-02T00:00:00Z</updated>
    <summary type="text">Apply the security update from Oracle. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on February 2, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-22952/</id>
    <title>CVE-2023-22952 — SugarCRM Sugar (Sell, Serve, Enterprise)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-22952/"/>
    <updated>2023-02-02T00:00:00Z</updated>
    <summary type="text">Apply the security update from SugarCRM. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 2, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-5430/</id>
    <title>CVE-2018-5430 — TIBCO JasperReports</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-5430/"/>
    <updated>2022-12-29T00:00:00Z</updated>
    <summary type="text">Apply the security update from TIBCO. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on December 29, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-18809/</id>
    <title>CVE-2018-18809 — TIBCO JasperReports</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-18809/"/>
    <updated>2022-12-29T00:00:00Z</updated>
    <summary type="text">Apply the security update from TIBCO. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on December 29, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-24706/</id>
    <title>CVE-2022-24706 — Apache CouchDB</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-24706/"/>
    <updated>2022-08-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from Apache. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-22536/</id>
    <title>CVE-2022-22536 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-22536/"/>
    <updated>2022-08-18T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 18, 2022.</summary>
  </entry>
</feed>
