<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:21:36.951165+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-06476</id>
    <title>bdu:2022-06476</title>
    <updated>2026-10-03T18:21:37.194366+00:00</updated>
    <content>bdu:2022-06476</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-06476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-490</id>
    <title>certfr-2021-avi-490 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-03T18:21:37.194427+00:00</updated>
    <content>certfr-2021-avi-490</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258290</id>
    <title>EUVD-2026-258290</title>
    <updated>2026-10-03T18:21:37.194466+00:00</updated>
    <content>EUVD-2026-258290</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258290"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-23358</id>
    <title>fkie_cve-2021-23358</title>
    <updated>2026-10-03T18:21:37.194491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-23358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cf4h-3jhx-xvhq</id>
    <title>GHSA-cf4h-3jhx-xvhq — Arbitrary Code Execution in underscore</title>
    <updated>2026-10-03T18:21:37.194523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: underscore</p>
<p>The package `underscore` from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cf4h-3jhx-xvhq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-23358</id>
    <title>gsd-2021-23358</title>
    <updated>2026-10-03T18:21:37.194547+00:00</updated>
    <content>gsd-2021-23358</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-23358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-23358</id>
    <title>msrc_CVE-2021-23358 — Arbitrary Code Injection</title>
    <updated>2026-10-03T18:21:37.194559+00:00</updated>
    <content>msrc_CVE-2021-23358</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-23358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1174</id>
    <title>OESA-2021-1174 — nodejs-underscore security update</title>
    <updated>2026-10-03T18:21:37.194575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: nodejs-underscore</p>
<p>Underscore.js is a utility-belt library for JavaScript that provides support for the usual functional suspects (each, map, reduce, filter...) without extending any core JavaScript objects.

Security Fix(es):

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.(CVE-2021-23358)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1174"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0601-1</id>
    <title>openSUSE-SU-2021:0601-1 — Security update for nodejs-underscore</title>
    <updated>2026-10-03T18:21:37.194597+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs-underscore</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0601-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oxas-adv-2025-0001</id>
    <title>OXAS-ADV-2025-0001 — OX App Suite Security Advisory OXAS-ADV-2025-0001</title>
    <updated>2026-10-03T18:21:37.194612+00:00</updated>
    <content>OXAS-ADV-2025-0001</content>
    <link href="https://cve.radiocsirt.org/vuln/oxas-adv-2025-0001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:1448</id>
    <title>RHSA-2021:1448 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.0.10 security and bug fix updates</title>
    <updated>2026-10-03T18:21:37.194627+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-underscore: Arbitrary code execution via the template function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:1448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23358</id>
    <title>UBUNTU-CVE-2021-23358</title>
    <updated>2026-10-03T18:21:37.194643+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: underscore, Ubuntu:16.04:LTS: underscore, Ubuntu:18.04:LTS: underscore, Ubuntu:20.04:LTS: underscore</p>
<p>The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354</id>
    <title>WID-SEC-W-2022-1354 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-03T18:21:37.194667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354"/>
  </entry>
</feed>
