<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:07:29.650822+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234423</id>
    <title>EUVD-2026-234423</title>
    <updated>2026-10-03T04:07:29.763428+00:00</updated>
    <content>EUVD-2026-234423</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23647</id>
    <title>fkie_cve-2022-23647</title>
    <updated>2026-10-03T04:07:29.763466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code. Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted. This bug has been fixed in v1.27.0. As a workaround, do not use the command line plugin on untrusted inputs, or sanitize all code blocks (remove all HTML code text) from all code blocks that use the command line plugin.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-23647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3949-f494-cm99</id>
    <title>GHSA-3949-f494-cm99 — Cross-site Scripting in Prism</title>
    <updated>2026-10-03T04:07:29.763503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: prismjs</p>
<p>### Impact
Prism's [Command line plugin](https://prismjs.com/plugins/command-line/) can be used by attackers to achieve an XSS attack. The Command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code.</p>
<p>Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted.</p>
<p>### Patches
This bug has been fixed in v1.27.0.</p>
<p>### Workarounds
Do not use the Command line plugin on untrusted inputs, or sanitized all code blocks (remove all HTML code text) from all code blocks that use the Command line plugin.</p>
<p>### References
- https://github.com/PrismJS/prism/pull/3341</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3949-f494-cm99"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-23647</id>
    <title>gsd-2022-23647</title>
    <updated>2026-10-03T04:07:29.763535+00:00</updated>
    <content>gsd-2022-23647</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-23647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6835</id>
    <title>RHSA-2022:6835 — Red Hat Security Advisory: Service Registry (container images) release and security update [2.3.0.GA]</title>
    <updated>2026-10-03T04:07:29.763548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>protobuf-java: potential DoS in the parsing procedure for binary data netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way cron-utils: template Injection leading to unauthenticated Remote Code Execution node-fetch: exposure of sensitive information to an unauthorized actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak quarkus: privilege escalation vulnerability with RestEasy Reactive scope leakage in Quarkus jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes prismjs: improperly escaped output allows a XSS node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery node-forge: Signature verification leniency in checking `DigestInfo` structure com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson snakeyaml: Denial of Service due to missing nested depth limitation for collections terser: insecure use of regular expressions leads to ReDoS postgresql-jdbc: Arbitrary File Write Vulnerability moment: inefficient parsing algorithm resulting in DoS graphql-java: DoS by malicious query</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23647</id>
    <title>UBUNTU-CVE-2022-23647</title>
    <updated>2026-10-03T04:07:29.763639+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-prismjs, Ubuntu:22.04:LTS: node-prismjs</p>
<p>Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code. Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted. This bug has been fixed in v1.27.0. As a workaround, do not use the command line plugin on untrusted inputs, or sanitize all code blocks (remove all HTML code text) from all code blocks that use the command line plugin.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0554</id>
    <title>WID-SEC-W-2023-0554 — IBM Maximo Asset Management: Schwachstelle ermöglicht Cross-Site Scripting</title>
    <updated>2026-10-03T04:07:29.763669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM Maximo Asset Management ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0554"/>
  </entry>
</feed>
