<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:06:46.287045+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0424</id>
    <title>certfr-2026-avi-0424 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T13:06:47.219699+00:00</updated>
    <content>certfr-2026-avi-0424</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0424"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366097</id>
    <title>EUVD-2026-366097</title>
    <updated>2026-10-03T13:06:47.219815+00:00</updated>
    <content>EUVD-2026-366097</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22029</id>
    <title>fkie_cve-2026-22029</title>
    <updated>2026-10-03T13:06:47.219847+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (&lt;BrowserRouter&gt;) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2w69-qvjg-hvjx</id>
    <title>GHSA-2w69-qvjg-hvjx — React Router vulnerable to XSS via Open Redirects</title>
    <updated>2026-10-03T13:06:47.219899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: react-router, npm: @remix-run/router</p>
<p>React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in [Framework Mode](https://reactrouter.com/start/modes#framework), [Data Mode](https://reactrouter.com/start/modes#data), or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if developers are creating redirect paths from untrusted content or via an open redirect.</p>
<p>&gt; [!NOTE]
&gt; This does not impact applications that use [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`&lt;BrowserRouter&gt;`).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2w69-qvjg-hvjx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10069-1</id>
    <title>openSUSE-SU-2026:10069-1 — heroic-games-launcher-2.18.1-2.1 on GA media</title>
    <updated>2026-10-03T13:06:47.219948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>heroic-games-launcher-2.18.1-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10069-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13542</id>
    <title>RHSA-2026:13542 — Red Hat Security Advisory: multicluster engine for Kubernetes v2.10.2 security update</title>
    <updated>2026-10-03T13:06:47.219977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lodash: prototype pollution in _.unset and _.omit functions golang: archive/tar: Unbounded allocation when parsing GNU sparse map golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption rhacm: Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution axios: Axios: Remote Code Execution via Prototype Pollution escalation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13542"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553</id>
    <title>WID-SEC-W-2026-0553 — HCL BigFix: Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:06:47.220029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553"/>
  </entry>
</feed>
