<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:30:59.932366+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07702</id>
    <title>bdu:2023-07702</title>
    <updated>2026-10-02T21:31:00.056613+00:00</updated>
    <content>bdu:2023-07702</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2019-avi-163</id>
    <title>certfr-2019-avi-163 — De multiples vulnérabilités ont été découvertes dans les produits
Fortinet. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-02T21:31:00.056650+00:00</updated>
    <content>certfr-2019-avi-163</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2019-avi-163"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-02374</id>
    <title>cnvd-2018-02374</title>
    <updated>2026-10-02T21:31:00.056670+00:00</updated>
    <content>cnvd-2018-02374</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-02374"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-113646</id>
    <title>EUVD-2026-113646</title>
    <updated>2026-10-02T21:31:00.056682+00:00</updated>
    <content>EUVD-2026-113646</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-113646"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2012-6708</id>
    <title>fkie_cve-2012-6708</title>
    <updated>2026-10-02T21:31:00.056692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '&lt;' character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the '&lt;' character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2012-6708"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2pqj-h3vj-pqgw</id>
    <title>GHSA-2pqj-h3vj-pqgw — Cross-Site Scripting in jquery</title>
    <updated>2026-10-02T21:31:00.056724+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: jquery, Maven: org.webjars.npm:jquery, NuGet: jQuery, RubyGems: jquery-rails</p>
<p>Affected versions of `jquery` are vulnerable to cross-site scripting. This occurs because the main `jquery` function uses a regular expression to differentiate between HTML and selectors, but does not properly anchor the regular expression. The result is that `jquery` may interpret HTML as selectors when given certain inputs, allowing for client side code execution.</p>
<p>## Proof of Concept
```
$("#log").html(
    $("element[attribute='&lt;img src=\"x\" onerror=\"alert(1)\" /&gt;']").html()
);
```</p>
<p>## Recommendation</p>
<p>Update to version 1.9.0 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2pqj-h3vj-pqgw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2012-6708</id>
    <title>gsd-2012-6708</title>
    <updated>2026-10-02T21:31:00.056759+00:00</updated>
    <content>gsd-2012-6708</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2012-6708"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-097-01</id>
    <title>ICSA-22-097-01 — Pepperl+Fuchs WirelessHART-Gateway</title>
    <updated>2026-10-02T21:31:00.056772+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected product allows active SSH and telnet services with hard-coded credentials.CVE-2021-34565 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). jQuery 3.0.0-rc.1 is vulnerable to a denial-of-service condition due to removing a logic a lowercased attribute names. Any attribute using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.CVE-2016-10707 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). If the application is not externally accessible or uses IP-based access restrictions, attackers can use DNS rebinding to bypass any IP or firewall-based access restrictions by proxying through their target's browser. This vulnerability only affects Versions 3.0.7 through 3.0.8.CVE-2021-34561 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). The filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability only affects Version 3.0.7.CVE-2021-33555 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). jQuery Version 1.4.2 allows…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-097-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2012-6708</id>
    <title>msrc_CVE-2012-6708 — jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differe…</title>
    <updated>2026-10-02T21:31:00.056840+00:00</updated>
    <content>msrc_CVE-2012-6708</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2012-6708"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0395-1</id>
    <title>openSUSE-SU-2020:0395-1 — Recommended update for ruby2.5</title>
    <updated>2026-10-02T21:31:00.056859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for ruby2.5</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:0395-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:0737-1</id>
    <title>SUSE-SU-2020:0737-1 — Recommended update for ruby2.5</title>
    <updated>2026-10-02T21:31:00.056877+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for ruby2.5</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:0737-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-6708</id>
    <title>UBUNTU-CVE-2012-6708</title>
    <updated>2026-10-02T21:31:00.056895+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jquery</p>
<p>jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '&lt;' character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the '&lt;' character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-6708"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-027</id>
    <title>VDE-2021-027 — Pepperl+Fuchs: WirelessHART-Gateway - Vulnerability may allow remote attackers to cause a Denial Of Service</title>
    <updated>2026-10-02T21:31:00.056917+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities have been discovered in the product and in the utilized components jQuery by jQuery Team and TLS Version 1.0/1.1.</p>
<p>The impact of the vulnerabilities on the affected device may result in</p>
<p>- denial of service
- remote code execution
- code exposure</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-024</id>
    <title>VDE-2025-024 — Wiesemann &amp; Theis: Multiple products from Wiesemann &amp; Theis support deprecated jQuery version</title>
    <updated>2026-10-02T21:31:00.056942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple W&amp;T devices are shipped with a jQuery version with a known XSS vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-024"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1752</id>
    <title>WID-SEC-W-2026-1752 — IBM Business Automation Workflow: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:31:00.056957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM Business Automation Workflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1752"/>
  </entry>
</feed>
