<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:38:47.029388+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10997</id>
    <title>bdu:2026-10997</title>
    <updated>2026-10-03T10:38:47.178085+00:00</updated>
    <content>bdu:2026-10997</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10997"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0021</id>
    <title>certfr-2025-avi-0021 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T10:38:47.178123+00:00</updated>
    <content>certfr-2025-avi-0021</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-41591</id>
    <title>cnvd-2020-41591</title>
    <updated>2026-10-03T10:38:47.178143+00:00</updated>
    <content>cnvd-2020-41591</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-41591"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-53955</id>
    <title>EUVD-2026-53955</title>
    <updated>2026-10-03T10:38:47.178155+00:00</updated>
    <content>EUVD-2026-53955</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-53955"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10768</id>
    <title>fkie_cve-2019-10768</title>
    <updated>2026-10-03T10:38:47.178167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-10768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-89mq-4x47-5v83</id>
    <title>GHSA-89mq-4x47-5v83 — angular Prototype Pollution vulnerability</title>
    <updated>2026-10-03T10:38:47.178193+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: angular</p>
<p>Versions of `angular ` prior to 1.7.9 are vulnerable to prototype pollution. The deprecated API function `merge()` does not restrict the modification of an Object's prototype in the , which may allow an attacker to add or modify an existing property that will exist on all objects.</p>
<p>## Recommendation</p>
<p>Upgrade to version 1.7.9 or later. The function was already deprecated and upgrades are not expected to break functionality.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-89mq-4x47-5v83"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-10768</id>
    <title>gsd-2019-10768</title>
    <updated>2026-10-03T10:38:47.178221+00:00</updated>
    <content>gsd-2019-10768</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-10768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-20-133-02</id>
    <title>ICSA-20-133-02 — OSIsoft PI System (Update A)</title>
    <updated>2026-10-03T10:38:47.178232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.CVE-2020-10610 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.CVE-2020-10608 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a shared workstation or terminal server deployment.CVE-2020-10606 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-20-133-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:5568</id>
    <title>RHSA-2020:5568 — Red Hat Security Advisory: Red Hat Fuse 7.8.0 release and security update</title>
    <updated>2026-10-03T10:38:47.178281+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jackson-modules-java8: DoS due to an Improper Input Validation thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol mysql-connector-java: privilege escalation in MySQL connector spring-ws: XML External Entity Injection (XXE) when receiving XML data from untrusted sources spring-batch: XML External Entity Injection (XXE) when receiving XML data from untrusted sources codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities hibernate-validator: safeHTML validator allows XSS AngularJS: Prototype pollution in merge function could result in code injection org.eclipse.paho.client.mqttv3: Improper hostname validation in the MQTT library cxf: does not restrict the number of message attachments cxf: OpenId Connect token service does not properly validate the clientId libquartz: XXE attacks via job description hibernate: SQL injection issue in Hibernate ORM batik: SSRF via "xlink:href" jetty: double release of resource can lead to information disclosure Undertow: Memory Leak in Undertow HttpOpenListener due to holding remoting connections indefinitely keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain tika: excessive memory usage in PSDParser apache-flink: JMX information disclosure vulnerability springframework: RFD attack via Content-Dispos…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:5568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10768</id>
    <title>UBUNTU-CVE-2019-10768</title>
    <updated>2026-10-03T10:38:47.178364+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: angular.js</p>
<p>In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10768"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0206</id>
    <title>WID-SEC-W-2023-0206 — Red Hat OpenStack (AngularJS): Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-03T10:38:47.178385+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenStack ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0206"/>
  </entry>
</feed>
