<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:39:38.248196+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08998</id>
    <title>bdu:2026-08998</title>
    <updated>2026-10-02T19:39:38.340871+00:00</updated>
    <content>bdu:2026-08998</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08998"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T19:39:38.340905+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ga82552</id>
    <title>CLEANSTART-2026-GA82552 — Babel is a compiler for writing next generation JavaScript</title>
    <updated>2026-10-02T19:39:38.340925+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: argo-workflows</p>
<p>Security vulnerability affects the argo-workflows package. Babel is a compiler for writing next generation JavaScript.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ga82552"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322304</id>
    <title>EUVD-2026-322304</title>
    <updated>2026-10-02T19:39:38.340952+00:00</updated>
    <content>EUVD-2026-322304</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44728</id>
    <title>fkie_cve-2026-44728</title>
    <updated>2026-10-02T19:39:38.340965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fv7c-fp4j-7gwp</id>
    <title>GHSA-fv7c-fp4j-7gwp — @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input</title>
    <updated>2026-10-02T19:39:38.340986+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @babel/plugin-transform-modules-systemjs</p>
<p>### Impact</p>
<p>Using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code.</p>
<p>Known affected plugins are:
- `@babel/plugin-transform-modules-systemjs`
- `@babel/preset-env` when using the [`modules: "systemjs"` option](https://babel.dev/docs/babel-preset-env#modules), as it delegates to `@babel/plugin-transform-modules-systemjs`</p>
<p>No other plugins under the `@babel` namespace are impacted.</p>
<p>**Users that only compile trusted code are not impacted.**</p>
<p>### Patches</p>
<p>The vulnerability has been fixed in `@babel/plugin-transform-modules-systemjs@7.29.4`.</p>
<p>Babel also released `@babel/preset-env@7.29.5`, updating its `@babel/plugin-transform-modules-systemjs` dependency, to simplify forcing the update if you are using `@babel/preset-env` directly.</p>
<p>### Workarounds</p>
<p>- Pin `@babel/parser` to v7.11.5. The downgrade will completely disable string module name parsing, but it would also disable other new language features and the build pipeline may fail as a result. Only do so if you are working on a legacy codebase and can not upgrade `@babel/plugin-transform-modules-systemjs` to v7.29.4.
- Do not use the `modules: "systemjs"` option, migrate the codebase to native ES Modules or any other module formats.</p>
<p>### Credits
Babel thanks Daniel Cervera for reporting the vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fv7c-fp4j-7gwp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44728</id>
    <title>UBUNTU-CVE-2026-44728</title>
    <updated>2026-10-02T19:39:38.341024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: node-babel7, Ubuntu:24.04:LTS: node-babel7, Ubuntu:25.10: node-babel7, Ubuntu:26.04:LTS: node-babel7</p>
<p>Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</id>
    <title>WID-SEC-W-2026-3046 — IBM Concert: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:39:38.341049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046"/>
  </entry>
</feed>
