<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:22:44.446886+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05598</id>
    <title>bdu:2022-05598</title>
    <updated>2026-10-03T00:22:44.463375+00:00</updated>
    <content>bdu:2022-05598</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05598"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0597</id>
    <title>certfr-2023-avi-0597 — De multiples vulnérabilités ont été découvertes dans&lt;span
class="textit"&gt; IBM Cognos Analytics&lt;/span&gt;. Certaines d'entr…</title>
    <updated>2026-10-03T00:22:44.463413+00:00</updated>
    <content>certfr-2023-avi-0597</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-68930</id>
    <title>cnvd-2022-68930</title>
    <updated>2026-10-03T00:22:44.463432+00:00</updated>
    <content>cnvd-2022-68930</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-68930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232638</id>
    <title>EUVD-2026-232638</title>
    <updated>2026-10-03T00:22:44.463443+00:00</updated>
    <content>EUVD-2026-232638</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232638"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36067</id>
    <title>fkie_cve-2022-36067</title>
    <updated>2026-10-03T00:22:44.463453+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-36067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mrgp-mrhc-5jrq</id>
    <title>GHSA-mrgp-mrhc-5jrq — vm2 vulnerable to Sandbox Escape resulting in Remote Code Execution on host</title>
    <updated>2026-10-03T00:22:44.463482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: vm2</p>
<p>### Impact
A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.</p>
<p>### Patches
This vulnerability was patched in the release of version `3.9.11` of `vm2`</p>
<p>### Workarounds
None.</p>
<p>### References
Github Issue - https://github.com/patriksimek/vm2/issues/467
The file that was patched - https://github.com/patriksimek/vm2/blob/master/lib/setup-sandbox.js#L71
The commit with the patch - https://github.com/patriksimek/vm2/commit/d9a7f3cc995d3d861e1380eafb886cb3c5e2b873#diff-b1a515a627d820118e76d0e323fe2f0589ed50a1eacb490f6c3278fe3698f164</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [VM2](https://github.com/patriksimek/vm2)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mrgp-mrhc-5jrq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-36067</id>
    <title>gsd-2022-36067</title>
    <updated>2026-10-03T00:22:44.463512+00:00</updated>
    <content>gsd-2022-36067</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-36067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6422</id>
    <title>RHSA-2022:6422 — Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.0.2 security and bug fixes</title>
    <updated>2026-10-03T00:22:44.463524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>moment: inefficient parsing algorithm resulting in DoS vm2: Sandbox Escape in vm2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6422"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1004</id>
    <title>WID-SEC-W-2023-1004 — vm2: Mehrere Schwachstellen</title>
    <updated>2026-10-03T00:22:44.463541+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um aus der Sandbox auszubrechen und beliebigen Code im Host-Kontext auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1004"/>
  </entry>
</feed>
