<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T11:26:05.699945+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233361</id>
    <title>EUVD-2026-233361</title>
    <updated>2026-10-07T11:26:05.780921+00:00</updated>
    <content>EUVD-2026-233361</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233361"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23466</id>
    <title>fkie_cve-2022-23466</title>
    <updated>2026-10-07T11:26:05.780961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the `/events` endpoint, the log data displayed on the dashboard are not sanitized. This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This vulnerability has been fixed on version `v2.0.0-rc.4`. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-23466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xr7p-8q82-878q</id>
    <title>GHSA-xr7p-8q82-878q — teler dashboard vulnerable to DOM-based cross-site scripting (XSS)</title>
    <updated>2026-10-07T11:26:05.780997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: teler.app</p>
<p>### Description</p>
<p>teler prior to version &lt;= 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the `/events` endpoint, the log data displayed on the dashboard are not sanitized.</p>
<p>### Impact</p>
<p>This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This indicates a low severity and there is no significant impact on the users.</p>
<p>### Affected Version</p>
<p>This issue was introduced from version `v2.0.0-rc` to `v2.0.0-rc.3` &amp; `v2.0.0-dev`.</p>
<p>### Patches</p>
<p>This vulnerability has been fixed on version `v2.0.0-rc.4` &amp; `v2.0.0-dev.2`.</p>
<p>### Workarounds</p>
<p>Here are some workarounds to handle this case:
- Deactivate the live event dashboard from the configuration file, or
- Upgrade teler version to `v2.0.0-rc.4` or `v2.0.0-dev.2` &amp; above.</p>
<p>### References</p>
<p>- https://github.com/kitabisa/teler/commit/20f59eda2420ac64e29f199a61230a0abc875e8e</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xr7p-8q82-878q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-23466</id>
    <title>gsd-2022-23466</title>
    <updated>2026-10-07T11:26:05.781040+00:00</updated>
    <content>gsd-2022-23466</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-23466"/>
  </entry>
</feed>
