<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:15:33.153063+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-15561</id>
    <title>bdu:2025-15561</title>
    <updated>2026-10-04T00:15:33.311964+00:00</updated>
    <content>bdu:2025-15561</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-15561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224</id>
    <title>certfr-2026-avi-0224 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T00:15:33.312009+00:00</updated>
    <content>certfr-2026-avi-0224</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-323847</id>
    <title>EUVD-2026-323847</title>
    <updated>2026-10-04T00:15:33.312028+00:00</updated>
    <content>EUVD-2026-323847</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-323847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66412</id>
    <title>fkie_cve-2025-66412</title>
    <updated>2026-10-04T00:15:33.312040+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-66412"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v4hv-rgfq-gp49</id>
    <title>GHSA-v4hv-rgfq-gp49 — Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes</title>
    <updated>2026-10-04T00:15:33.312074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @angular/compiler</p>
<p>A **Stored Cross-Site Scripting ([XSS](https://angular.dev/best-practices/security#preventing-cross-site-scripting-xss))** vulnerability has been identified in the **Angular Template Compiler**. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain [`javascript:` URLs](https://developer.mozilla.org/en-US/Web/URI/Reference/Schemes/javascript)) as requiring strict URL security, enabling the injection of malicious scripts.</p>
<p>Additionally, a related vulnerability exists involving SVG animation elements (`&lt;animate&gt;`, `&lt;set&gt;`, `&lt;animateMotion&gt;`, `&lt;animateTransform&gt;`). The `attributeName` attribute on these elements was not properly validated, allowing attackers to dynamically target security-sensitive attributes like `href` or `xlink:href` on other elements. By binding `attributeName` to "href" and providing a `javascript:` URL in the `values` or `to` attribute, an attacker could bypass sanitization and execute arbitrary code.</p>
<p>Attributes confirmed to be vulnerable include:
*   SVG-related attributes: (e.g., `xlink:href`), and various MathML attributes (e.g., `math|href`, `annotation|href`).
*   SVG animation `attributeName` attribute when bound to "href" or "xlink:href".</p>
<p>When template binding is used to assign untrusted, user-controlled data to these attributes (e.g., `[attr.xlink:href]=…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v4hv-rgfq-gp49"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-071-03</id>
    <title>ICSA-26-071-03 — Siemens SIDIS Prime</title>
    <updated>2026-10-04T00:15:33.312124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-071-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0079</id>
    <title>NCSC-2026-0079 — Kwetsbaarheden verholpen in Siemens producten</title>
    <updated>2026-10-04T00:15:33.312227+00:00</updated>
    <content>NCSC-2026-0079</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:33371</id>
    <title>RHSA-2026:33371 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.18 security update</title>
    <updated>2026-10-04T00:15:33.312300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression undertow: Undertow MadeYouReset HTTP/2 DDoS Vulnerability undertow-core: Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI angular: Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes ajv: ReDoS via $data reference io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:33371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-253495</id>
    <title>SSA-253495 — SSA-253495: Multiple Vulnerabilities in SINEC OS before V4.0</title>
    <updated>2026-10-04T00:15:33.312336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue. A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue. A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corrup…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-253495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66412</id>
    <title>UBUNTU-CVE-2025-66412</title>
    <updated>2026-10-04T00:15:33.312790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: angular.js, Ubuntu:Pro:18.04:LTS: angular.js, Ubuntu:Pro:20.04:LTS: angular.js, Ubuntu:22.04:LTS: angular.js, Ubuntu:24.04:LTS: angular.js, Ubuntu:25.10: angular.js, Ubuntu:26.04:LTS: angular.js</p>
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66412"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2708</id>
    <title>WID-SEC-W-2025-2708 — Angular: Schwachstelle ermöglicht Cross-Site Scripting</title>
    <updated>2026-10-04T00:15:33.312825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Angular ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2708"/>
  </entry>
</feed>
