<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:26:18.107175+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-01322</id>
    <title>bdu:2021-01322</title>
    <updated>2026-10-03T00:26:18.113903+00:00</updated>
    <content>bdu:2021-01322</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-01322"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-700</id>
    <title>certfr-2021-avi-700 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T00:26:18.113935+00:00</updated>
    <content>certfr-2021-avi-700</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-700"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-36460</id>
    <title>EUVD-2026-36460</title>
    <updated>2026-10-03T00:26:18.113954+00:00</updated>
    <content>EUVD-2026-36460</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-36460"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-5259</id>
    <title>fkie_cve-2020-5259</title>
    <updated>2026-10-03T00:26:18.113965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-5259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3hw5-q855-g6cw</id>
    <title>GHSA-3hw5-q855-g6cw — Prototype Pollution in Dojox</title>
    <updated>2026-10-03T00:26:18.113992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: dojox</p>
<p>The Dojox jQuery wrapper `jqMix` mixin method is vulnerable to Prototype Pollution.</p>
<p>Affected Area:
```
//https://github.com/dojo/dojox/blob/master/jq.js#L442
		var tobj = {};
		for(var x in props){
			// the "tobj" condition avoid copying properties in "props"
			// inherited from Object.prototype.  For example, if obj has a custom
			// toString() method, don't overwrite it with the toString() method
			// that props inherited from Object.prototype
			if((tobj[x] === undefined || tobj[x] != props[x]) &amp;&amp; props[x] !== undefined &amp;&amp; obj != props[x]){
				if(dojo.isObject(obj[x]) &amp;&amp; dojo.isObject(props[x])){
					if(dojo.isArray(props[x])){
						obj[x] = props[x];
					}else{
						obj[x] = jqMix(obj[x], props[x]);
					}
				}else{
					obj[x] = props[x];
				}
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3hw5-q855-g6cw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-5259</id>
    <title>gsd-2020-5259</title>
    <updated>2026-10-03T00:26:18.114024+00:00</updated>
    <content>gsd-2020-5259</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-5259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-5259</id>
    <title>UBUNTU-CVE-2020-5259</title>
    <updated>2026-10-03T00:26:18.114035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: dojo, Ubuntu:18.04:LTS: dojo, Ubuntu:Pro:20.04:LTS: dojo</p>
<p>In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-5259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</id>
    <title>WID-SEC-W-2023-0809 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
    <updated>2026-10-03T00:26:18.114057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809"/>
  </entry>
</feed>
