<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:49:54.202365+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2022-23491</id>
    <title>BREW-azure-cli-CVE-2022-23491 — Certifi removing TrustCor root certificate</title>
    <updated>2026-10-03T01:49:54.544413+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: azure-cli</p>
<p>Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store.</p>
<p>TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found [here](https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/yLohoVqtCgAJ).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2022-23491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0086</id>
    <title>certfr-2023-avi-0086 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T01:49:54.544498+00:00</updated>
    <content>certfr-2023-avi-0086</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233357</id>
    <title>EUVD-2026-233357</title>
    <updated>2026-10-03T01:49:54.544521+00:00</updated>
    <content>EUVD-2026-233357</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23491</id>
    <title>fkie_cve-2022-23491</title>
    <updated>2026-10-03T01:49:54.544535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-23491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-43fp-rhv2-5gv8</id>
    <title>GHSA-43fp-rhv2-5gv8 — Certifi removing TrustCor root certificate</title>
    <updated>2026-10-03T01:49:54.544570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: certifi</p>
<p>Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store.</p>
<p>TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found [here](https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/yLohoVqtCgAJ).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-43fp-rhv2-5gv8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-23491</id>
    <title>gsd-2022-23491</title>
    <updated>2026-10-03T01:49:54.544596+00:00</updated>
    <content>gsd-2022-23491</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-23491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1457</id>
    <title>OESA-2023-1457 — python-certifi security update</title>
    <updated>2026-10-03T01:49:54.544609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: python-certifi, openEuler:20.03-LTS-SP3: python-certifi, openEuler:22.03-LTS: python-certifi, openEuler:22.03-LTS-SP1: python-certifi, openEuler:22.03-LTS-SP2: python-certifi</p>
<p>Certifi provides Mozilla carefully curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. It has been extracted from the Requests project

Security Fix(es):

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from &amp;quot;TrustCor&amp;quot; from the root store. These are in the process of being removed from Mozilla&amp;apos;s trust store. TrustCor&amp;apos;s root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor&amp;apos;s ownership also operated a business that produced spyware. Conclusions of Mozilla&amp;apos;s investigation can be found in the linked google group discussion.(CVE-2022-23491)

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes &amp;quot;e-Tugra&amp;quot; root certificates. e-Tugra&amp;apos;s root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from &amp;quot;e-Tugra&amp;quot; from the root store.(CVE-2023-37920)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1457"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13237-1</id>
    <title>openSUSE-SU-2024:13237-1 — python310-certifi-2023.7.22-2.1 on GA media</title>
    <updated>2026-10-03T01:49:54.544661+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-certifi-2023.7.22-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13237-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2022-42986</id>
    <title>PYSEC-2022-42986</title>
    <updated>2026-10-03T01:49:54.544681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: certifi</p>
<p>Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2022-42986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:0589</id>
    <title>RHBA-2023:0589 — Red Hat Bug Fix Advisory: Red Hat Ansible Automation Platform 2.3 Product Release Update</title>
    <updated>2026-10-03T01:49:54.544704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-certifi: untrusted root certificates</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:0589"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:0118-1</id>
    <title>SUSE-SU-2023:0118-1 — Security update for mozilla-nss</title>
    <updated>2026-10-03T01:49:54.544721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for mozilla-nss</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:0118-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23491</id>
    <title>UBUNTU-CVE-2022-23491</title>
    <updated>2026-10-03T01:49:54.544737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ca-certificates, Ubuntu:Pro:16.04:LTS: ca-certificates, Ubuntu:18.04:LTS: ca-certificates, Ubuntu:20.04:LTS: ca-certificates, Ubuntu:22.04:LTS: ca-certificates</p>
<p>Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0255</id>
    <title>WID-SEC-W-2023-0255 — IBM Spectrum Protect: Mehrere Schwachstellen</title>
    <updated>2026-10-03T01:49:54.544764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen und einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0255"/>
  </entry>
</feed>
