<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:57:24.989398+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2020:5499</id>
    <title>ALSA-2020:5499 — Moderate: nodejs:12 security and bug fix update</title>
    <updated>2026-10-03T14:57:25.288574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>Security Fix(es):</p>
<p>* nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774)</p>
<p>* c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS (CVE-2020-8277)</p>
<p>* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* yarn install crashes with nodejs:12 on aarch64 (BZ#1901045)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2020:5499"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</id>
    <title>certfr-2022-avi-278 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
discover. Certaines d'entre elles permettent à un att…</title>
    <updated>2026-10-03T14:57:25.288647+00:00</updated>
    <content>certfr-2022-avi-278</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-278"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42876</id>
    <title>EUVD-2026-42876</title>
    <updated>2026-10-03T14:57:25.288669+00:00</updated>
    <content>EUVD-2026-42876</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42876"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15366</id>
    <title>fkie_cve-2020-15366</title>
    <updated>2026-10-03T14:57:25.288683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-15366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v88g-cgmw-v5xw</id>
    <title>GHSA-v88g-cgmw-v5xw — Prototype Pollution in Ajv</title>
    <updated>2026-10-03T14:57:25.288707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: ajv</p>
<p>An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v88g-cgmw-v5xw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-15366</id>
    <title>gsd-2020-15366</title>
    <updated>2026-10-03T14:57:25.288727+00:00</updated>
    <content>gsd-2020-15366</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-15366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1620</id>
    <title>OESA-2022-1620 — nodejs security update</title>
    <updated>2026-10-03T14:57:25.288739+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: nodejs, openEuler:20.03-LTS-SP2: nodejs, openEuler:20.03-LTS-SP3: nodejs</p>
<p>Node.js is a platform built on Chrome&amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.



Security Fix(es):

An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)(CVE-2020-15366)

The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a &amp;quot;purpose&amp;quot; has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named &amp;quot;purpose&amp;quot; values implemented in libcrypto…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1620"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:4298</id>
    <title>RHSA-2020:4298 — Red Hat Security Advisory: OpenShift Container Platform 4.6.1 image security update</title>
    <updated>2026-10-03T14:57:25.288801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SSL/TLS: CBC padding timing attack (lucky-13) grafana: XSS vulnerability via a column style on the "Dashboard &gt; Table Panel" screen jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06) nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser nodejs-lodash: prototype pollution in zipObjectDeep function kubernetes: compromised node could escalate to cluster level privileges golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic openshift/console: text injection on error page via crafted url kibana: X-Frame-Option not set by default might lead to clickjacking jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &lt;option&gt; tag in HTML passed to DOM manipulation methods grafana: stored XSS grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash open…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:4298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:5499</id>
    <title>RHSA-2020:5499 — Red Hat Security Advisory: nodejs:12 security and bug fix update</title>
    <updated>2026-10-03T14:57:25.288861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-yargs-parser: prototype pollution vulnerability nodejs-y18n: prototype pollution vulnerability c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:5499"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15366</id>
    <title>UBUNTU-CVE-2020-15366</title>
    <updated>2026-10-03T14:57:25.288881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-ajv, Ubuntu:20.04:LTS: node-ajv</p>
<p>An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-15366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</id>
    <title>WID-SEC-W-2023-0809 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:57:25.288902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809"/>
  </entry>
</feed>
