<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:47:24.826509+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01281</id>
    <title>bdu:2026-01281</title>
    <updated>2026-10-03T22:47:25.038240+00:00</updated>
    <content>bdu:2026-01281</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01281"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337734</id>
    <title>EUVD-2026-337734</title>
    <updated>2026-10-03T22:47:25.038282+00:00</updated>
    <content>EUVD-2026-337734</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337734"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59057</id>
    <title>fkie_cve-2025-59057</title>
    <updated>2026-10-03T22:47:25.038308+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/&lt;Meta&gt; APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the application is being used in Declarative Mode (&lt;BrowserRouter&gt;) or Data Mode (createBrowserRouter/&lt;RouterProvider&gt;). This issue has been patched in @remix-run/react version 2.17.1 and react-router version 7.9.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-59057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3cgp-3xvw-98x8</id>
    <title>GHSA-3cgp-3xvw-98x8 — React Router has XSS Vulnerability</title>
    <updated>2026-10-03T22:47:25.038348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: react-router, npm: @remix-run/react</p>
<p>A XSS vulnerability exists in in React Router's `meta()`/`&lt;Meta&gt;` APIs in [Framework Mode](https://reactrouter.com/start/modes#framework) when generating `script:ld+json` tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag.</p>
<p>&gt; [!NOTE]
&gt; This does not impact applications using [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`&lt;BrowserRouter&gt;`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`&lt;RouterProvider&gt;`).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3cgp-3xvw-98x8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:19712</id>
    <title>RHSA-2026:19712 — Red Hat Security Advisory: RHOAI 3.3.3 - Red Hat OpenShift AI</title>
    <updated>2026-10-03T22:47:25.038381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vllm: Server Side request forgery (SSRF) in MediaConnector node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing react-router: @remix-run/router: React Router XSS Vulnerability golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate vllm: VLLM deserialization vulnerability leading to DoS and potential RCE axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization glob: glob: Command Injection Vulnerability via Malicious Filenames node-forge: node-forge ASN.1 Unbounded Recursion urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion vllm: vLLM: Remote Code Execution via malicious model configuration urllib3: urllib3 Streaming API improperly handles highly compressed data aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb ajv: ReDoS via $data reference nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function nltk: NLTK: Arbitrary file read via path traversal vulnerability lodash: lodash: Arbitrary code execution via untrusted input in template imports urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming A…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:19712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0752</id>
    <title>WID-SEC-W-2026-0752 — IBM SPSS: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:47:25.038481+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM SPSS ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0752"/>
  </entry>
</feed>
