<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T13:36:44.449703+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-166229</id>
    <title>EUVD-2026-166229</title>
    <updated>2026-10-07T13:36:44.542664+00:00</updated>
    <content>EUVD-2026-166229</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-166229"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7677</id>
    <title>fkie_cve-2020-7677</title>
    <updated>2026-10-07T13:36:44.542703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-7677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-29xr-v42j-r956</id>
    <title>GHSA-29xr-v42j-r956 — thenify before 3.3.1 made use of unsafe calls to `eval`.</title>
    <updated>2026-10-07T13:36:44.542736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: thenify, Maven: org.webjars.npm:thenify</p>
<p>Versions of thenify prior to 3.3.1 made use of unsafe calls to `eval`. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to `eval`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-29xr-v42j-r956"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-7677</id>
    <title>gsd-2020-7677</title>
    <updated>2026-10-07T13:36:44.542763+00:00</updated>
    <content>gsd-2020-7677</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-7677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7677</id>
    <title>UBUNTU-CVE-2020-7677</title>
    <updated>2026-10-07T13:36:44.542776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-thenify, Ubuntu:20.04:LTS: node-thenify</p>
<p>This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7677"/>
  </entry>
</feed>
