<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:52:39.375987+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:1846</id>
    <title>ALSA-2021:1846 — Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update</title>
    <updated>2026-10-02T10:52:40.643227+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bind-dyndb-ldap, AlmaLinux:8: custodia, AlmaLinux:8: opendnssec, AlmaLinux:8: python3-custodia, AlmaLinux:8: python3-jwcrypto, AlmaLinux:8: python3-kdcproxy, AlmaLinux:8: python3-pyusb, AlmaLinux:8: python3-qrcode, AlmaLinux:8: python3-qrcode-core, AlmaLinux:8: python3-yubico and 2 more</p>
<p>AlmaLinux Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.</p>
<p>Security Fix(es):</p>
<p>* jquery: Passing HTML containing &lt;option&gt; elements to manipulation methods could result in untrusted code execution (CVE-2020-11023)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:1846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-04949</id>
    <title>bdu:2020-04949</title>
    <updated>2026-10-02T10:52:40.643344+00:00</updated>
    <content>bdu:2020-04949</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-04949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-drupal-2020-11023</id>
    <title>BIT-drupal-2020-11023 — Potential XSS vulnerability in jQuery</title>
    <updated>2026-10-02T10:52:40.643363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: drupal</p>
<p>In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing &lt;option&gt; elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-drupal-2020-11023"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-310</id>
    <title>certfr-2020-avi-310 — De multiples vulnérabilités ont été découvertes dans Drupal. Elles
permettent à un attaquant de provoquer un contournem…</title>
    <updated>2026-10-02T10:52:40.643387+00:00</updated>
    <content>certfr-2020-avi-310</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-310"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-dl38300</id>
    <title>CLEANSTART-2024-DL38300 — In jQuery versions greater than or equal to 1</title>
    <updated>2026-10-02T10:52:40.643403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: cacti, CleanStart: drupal7</p>
<p>CVE-2020-11023 affects multiple packages. In jQuery versions greater than or equal to 1. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-dl38300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-27491</id>
    <title>cnvd-2020-27491</title>
    <updated>2026-10-02T10:52:40.643425+00:00</updated>
    <content>cnvd-2020-27491</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-27491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2025:2436</id>
    <title>ESSA-2025:2436 — Moderate: tbb security update</title>
    <updated>2026-10-02T10:52:40.643437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Moderate: tbb security update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2025:2436"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256107</id>
    <title>EUVD-2026-256107</title>
    <updated>2026-10-02T10:52:40.643454+00:00</updated>
    <content>EUVD-2026-256107</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256107"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11023</id>
    <title>fkie_cve-2020-11023</title>
    <updated>2026-10-02T10:52:40.643465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing &lt;option&gt; elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-11023"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202601</id>
    <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
    <updated>2026-10-02T10:52:40.643487+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.</p>
<p>This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.</p>
<p>Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jpcq-cgw6-v4j6</id>
    <title>GHSA-jpcq-cgw6-v4j6 — Potential XSS vulnerability in jQuery</title>
    <updated>2026-10-02T10:52:40.643574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: jquery, RubyGems: jquery-rails, NuGet: jQuery, Maven: org.webjars.npm:jquery, Packagist: components/jquery</p>
<p>### Impact
Passing HTML containing `&lt;option&gt;` elements from untrusted sources - even after sanitizing them - to one of jQuery's DOM manipulation methods (i.e. `.html()`, `.append()`, and others) may execute untrusted code.</p>
<p>### Patches
This problem is patched in jQuery 3.5.0.</p>
<p>### Workarounds
To workaround this issue without upgrading, use [DOMPurify](https://github.com/cure53/DOMPurify) with its `SAFE_FOR_JQUERY` option to sanitize the HTML string before passing it to a jQuery method.</p>
<p>### References
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/</p>
<p>### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery repo](https://github.com/jquery/jquery/issues). If you don't find an answer, open a new issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jpcq-cgw6-v4j6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-11023</id>
    <title>gsd-2020-11023</title>
    <updated>2026-10-02T10:52:40.643607+00:00</updated>
    <content>gsd-2020-11023</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-11023"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-306-01</id>
    <title>ICSA-21-306-01 — Sensormatic Electronics VideoEdge</title>
    <updated>2026-10-02T10:52:40.643618+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the JQuery web user interface (UI) component could allow a webpage to be altered before it is served to users.CVE-2020-11023 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-306-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:1079</id>
    <title>RHBA-2025:1079 — Red Hat Bug Fix Advisory: Red Hat Quay v3.13.4 bug fix release</title>
    <updated>2026-10-02T10:52:40.643635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jquery: Untrusted code execution via &lt;option&gt; tag in HTML passed to DOM manipulation methods</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:1079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2025-189-02</id>
    <title>SEVD-2025-189-02 — System Monitor Application in Harmony and Pro-face PS5000 Legacy Industrial PCs</title>
    <updated>2026-10-02T10:52:40.643651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in its System Monitor application of Harmony Industrial PC and 
Pro-face PS5000 trusted Legacy industrial PC series products.
The Harmony Industrial PC Series and Pro-face PS5000 legacy industrial PC Series are iPCs which 
incorporate slim, flexible and durable design allowing each customer to configure their iPC based on their 
individual application needs. These products offer flexible connectivity to a range of devices and designs. 
Failure to apply the remediations provided below may risk untrusted code execution which could result in 
operational failures.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2025-189-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11023</id>
    <title>UBUNTU-CVE-2020-11023</title>
    <updated>2026-10-02T10:52:40.643670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: drupal7, Ubuntu:Pro:16.04:LTS: drupal7, Ubuntu:Pro:18.04:LTS: jquery, Ubuntu:20.04:LTS: jquery</p>
<p>In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing &lt;option&gt; elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11023"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-027</id>
    <title>VDE-2021-027 — Pepperl+Fuchs: WirelessHART-Gateway - Vulnerability may allow remote attackers to cause a Denial Of Service</title>
    <updated>2026-10-02T10:52:40.643694+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities have been discovered in the product and in the utilized components jQuery by jQuery Team and TLS Version 1.0/1.1.</p>
<p>The impact of the vulnerabilities on the affected device may result in</p>
<p>- denial of service
- remote code execution
- code exposure</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1347</id>
    <title>WID-SEC-W-2022-1347 — jQuery: Mehrere Schwachstellen ermöglichen Cross-Site Scripting</title>
    <updated>2026-10-02T10:52:40.643718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in jQuery ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1347"/>
  </entry>
</feed>
