<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:41:28.149464+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279</id>
    <title>certfr-2025-avi-0279 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T17:41:28.159679+00:00</updated>
    <content>certfr-2025-avi-0279</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257771</id>
    <title>EUVD-2026-257771</title>
    <updated>2026-10-03T17:41:28.159720+00:00</updated>
    <content>EUVD-2026-257771</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257771"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-6485</id>
    <title>fkie_cve-2024-6485</title>
    <updated>2026-10-03T17:41:28.159735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-6485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vxmc-5x29-h64v</id>
    <title>GHSA-vxmc-5x29-h64v — Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes</title>
    <updated>2026-10-03T17:41:28.159764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: bootstrap</p>
<p>A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vxmc-5x29-h64v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-6485</id>
    <title>msrc_CVE-2024-6485 — XSS in Bootstrap button component</title>
    <updated>2026-10-03T17:41:28.159787+00:00</updated>
    <content>msrc_CVE-2024-6485</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-6485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:1249</id>
    <title>RHSA-2025:1249 — Red Hat Security Advisory: updated discovery container images</title>
    <updated>2026-10-03T17:41:28.159803+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jquery: Untrusted code execution via &lt;option&gt; tag in HTML passed to DOM manipulation methods PostCSS: Improper input validation in PostCSS bootstrap: Cross-Site Scripting via button plugin on bootstrap ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging http-proxy-middleware: http-proxy-middleware: Denial of Service via unhandled error during path matching cross-spawn: regular expression denial of service redis: Denial-of-service due to unbounded pattern matching in Redis redis: Lua library commands may lead to stack overflow and RCE in Redis axios: axios: Server-Side Request Forgery python-django: Memory exhaustion in django.utils.numberformat.floatformat() python-django: Potential denial-of-service vulnerability in django.utils.html.urlize() and AdminURLFieldWidget python-django: Potential SQL injection in QuerySet.values() and values_list() webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule express: Improper Input Handling in Express Redirects send: Code Execution Vulnerability in Send Library serve-static: Improper Sanitization in serve-static path-to-regexp: Backtracking regular expressions cause ReDoS body-parser: Denial of Service Vulnerability in body-parser redis: Redis' Lua library commands may lead to remote code execution path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x django: Potential denial-of-service in django.utils.html.strip_tags() nanoid: nanoid mishandles non-integer val…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:1249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6485</id>
    <title>UBUNTU-CVE-2024-6485</title>
    <updated>2026-10-03T17:41:28.159851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: twitter-bootstrap3, Ubuntu:Pro:18.04:LTS: twitter-bootstrap3, Ubuntu:22.04:LTS: twitter-bootstrap3, Ubuntu:24.04:LTS: twitter-bootstrap3</p>
<p>A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1606</id>
    <title>WID-SEC-W-2024-1606 — Bootstrap: Mehrere Schwachstellen ermöglichen Cross-Site Scripting</title>
    <updated>2026-10-03T17:41:28.159887+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Bootstrap ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1606"/>
  </entry>
</feed>
