<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:27:05.041228+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02118</id>
    <title>bdu:2024-02118</title>
    <updated>2026-10-03T14:27:05.354233+00:00</updated>
    <content>bdu:2024-02118</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02118"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0090</id>
    <title>certfr-2024-avi-0090 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T14:27:05.354284+00:00</updated>
    <content>certfr-2024-avi-0090</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-161340</id>
    <title>EUVD-2026-161340</title>
    <updated>2026-10-03T14:27:05.354305+00:00</updated>
    <content>EUVD-2026-161340</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-161340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-45857</id>
    <title>fkie_cve-2023-45857</title>
    <updated>2026-10-03T14:27:05.354317+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-45857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wf5p-g6vw-rhxx</id>
    <title>GHSA-wf5p-g6vw-rhxx — Axios Cross-Site Request Forgery Vulnerability</title>
    <updated>2026-10-03T14:27:05.354347+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: axios</p>
<p>An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wf5p-g6vw-rhxx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-45857</id>
    <title>gsd-2023-45857</title>
    <updated>2026-10-03T14:27:05.354373+00:00</updated>
    <content>gsd-2023-45857</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-45857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-277-02</id>
    <title>ICSA-24-277-02 — Subnet Solutions Inc. PowerSYSTEM Center</title>
    <updated>2026-10-03T14:27:05.354384+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vulnerable versions of PowerSYSTEM Center utilize Axios NPM package 0.21.0, which contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Vulnerable versions of PowerSYSTEM Center utilize Axios, which is vulnerable to Inefficient Regular Expression Complexity. Vulnerable versions of PowerSYSTEM Center utilize Axios 1.5.1, which can inadvertently reveal the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host, allowing attackers to view sensitive information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-277-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-45857</id>
    <title>msrc_CVE-2023-45857 — An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it…</title>
    <updated>2026-10-03T14:27:05.354408+00:00</updated>
    <content>msrc_CVE-2023-45857</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-45857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1640</id>
    <title>RHSA-2024:1640 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update</title>
    <updated>2026-10-03T14:27:05.354426+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests GitPython: Blind local file inclusion axios: exposure of confidential data stored in cookies python-twisted: disordered HTTP pipeline response in twisted.web python-aiohttp: numerous issues in HTTP parser with header parsing python-cryptography: NULL-dereference when loading PKCS7 certificates golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads jinja2: HTML attribute injection when passing user input as keys to xmlattr filter aiohttp: follow_symlinks directory traversal vulnerability python-aiohttp: http request smuggling Django: denial-of-service in ``intcomma`` template filter python-django: Potential regular expression denial-of-service in django.utils.text.Truncator.words()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1640"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45857</id>
    <title>UBUNTU-CVE-2023-45857</title>
    <updated>2026-10-03T14:27:05.354465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:25.10: node-axios, Ubuntu:Pro:26.04:LTS: node-axios</p>
<p>An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0277</id>
    <title>WID-SEC-W-2024-0277 — IBM Business Automation Workflow: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:27:05.354492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Business Automation Workflow ausnutzen, um einen Cross-Site-Scripting-Angriff zu starten, einen Phishing-Angriff durchzuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0277"/>
  </entry>
</feed>
