<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:31:01 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-07702</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07702</link>
      <description>bdu:2023-07702</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07702</guid>
    </item>
    <item>
      <title>certfr-2019-avi-163 — De multiples vulnérabilités ont été découvertes dans les produits
Fortinet. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-163</link>
      <description>certfr-2019-avi-163</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-163</guid>
    </item>
    <item>
      <title>cnvd-2018-02374</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-02374</link>
      <description>cnvd-2018-02374</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-02374</guid>
    </item>
    <item>
      <title>EUVD-2026-113646</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-113646</link>
      <description>EUVD-2026-113646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-113646</guid>
    </item>
    <item>
      <title>fkie_cve-2012-6708</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2012-6708</link>
      <description>&lt;p&gt;jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the &amp;#39;&amp;lt;&amp;#39; character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the &amp;#39;&amp;lt;&amp;#39; character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the &amp;#39;&amp;lt;&amp;#39; character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the &amp;#39;&amp;lt;&amp;#39; character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2012-6708</guid>
    </item>
    <item>
      <title>GHSA-2pqj-h3vj-pqgw — Cross-Site Scripting in jquery</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2pqj-h3vj-pqgw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jquery, Maven: org.webjars.npm:jquery, NuGet: jQuery, RubyGems: jquery-rails&lt;/p&gt;
&lt;p&gt;Affected versions of `jquery` are vulnerable to cross-site scripting. This occurs because the main `jquery` function uses a regular expression to differentiate between HTML and selectors, but does not properly anchor the regular expression. The result is that `jquery` may interpret HTML as selectors when given certain inputs, allowing for client side code execution.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```
$(&amp;#34;#log&amp;#34;).html(
    $(&amp;#34;element[attribute=&amp;#39;&amp;lt;img src=\&amp;#34;x\&amp;#34; onerror=\&amp;#34;alert(1)\&amp;#34; /&amp;gt;&amp;#39;]&amp;#34;).html()
);
```&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Update to version 1.9.0 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jquery, Maven: org.webjars.npm:jquery, NuGet: jQuery, RubyGems: jquery-rails&lt;/p&gt;
&lt;p&gt;Affected versions of `jquery` are vulnerable to cross-site scripting. This occurs because the main `jquery` function uses a regular expression to differentiate between HTML and selectors, but does not properly anchor the regular expression. The result is that `jquery` may interpret HTML as selectors when given certain inputs, allowing for client side code execution.&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```
$(&amp;#34;#log&amp;#34;).html(
    $(&amp;#34;element[attribute=&amp;#39;&amp;lt;img src=\&amp;#34;x\&amp;#34; onerror=\&amp;#34;alert(1)\&amp;#34; /&amp;gt;&amp;#39;]&amp;#34;).html()
);
```&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Update to version 1.9.0 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2pqj-h3vj-pqgw</guid>
    </item>
    <item>
      <title>gsd-2012-6708</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2012-6708</link>
      <description>gsd-2012-6708</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2012-6708</guid>
    </item>
    <item>
      <title>ICSA-22-097-01 — Pepperl+Fuchs WirelessHART-Gateway</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-097-01</link>
      <description>&lt;p&gt;The affected product allows active SSH and telnet services with hard-coded credentials.CVE-2021-34565 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). jQuery 3.0.0-rc.1 is vulnerable to a denial-of-service condition due to removing a logic a lowercased attribute names. Any attribute using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.CVE-2016-10707 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). If the application is not externally accessible or uses IP-based access restrictions, attackers can use DNS rebinding to bypass any IP or firewall-based access restrictions by proxying through their target&amp;#39;s browser. This vulnerability only affects Versions 3.0.7 through 3.0.8.CVE-2021-34561 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). The filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability only affects Version 3.0.7.CVE-2021-33555 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). jQuery Version 1.4.2 allows…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product allows active SSH and telnet services with hard-coded credentials.CVE-2021-34565 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). jQuery 3.0.0-rc.1 is vulnerable to a denial-of-service condition due to removing a logic a lowercased attribute names. Any attribute using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.CVE-2016-10707 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). If the application is not externally accessible or uses IP-based access restrictions, attackers can use DNS rebinding to bypass any IP or firewall-based access restrictions by proxying through their target&amp;#39;s browser. This vulnerability only affects Versions 3.0.7 through 3.0.8.CVE-2021-34561 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). The filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability only affects Version 3.0.7.CVE-2021-33555 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). jQuery Version 1.4.2 allows…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-097-01</guid>
    </item>
    <item>
      <title>msrc_CVE-2012-6708 — jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differe…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2012-6708</link>
      <description>msrc_CVE-2012-6708</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2012-6708</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0395-1 — Recommended update for ruby2.5</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0395-1</link>
      <description>&lt;p&gt;Recommended update for ruby2.5&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for ruby2.5&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0395-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:0737-1 — Recommended update for ruby2.5</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:0737-1</link>
      <description>&lt;p&gt;Recommended update for ruby2.5&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for ruby2.5&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:0737-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2012-6708</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-6708</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jquery&lt;/p&gt;
&lt;p&gt;jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the &amp;#39;&amp;lt;&amp;#39; character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the &amp;#39;&amp;lt;&amp;#39; character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jquery&lt;/p&gt;
&lt;p&gt;jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the &amp;#39;&amp;lt;&amp;#39; character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the &amp;#39;&amp;lt;&amp;#39; character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2012-6708</guid>
    </item>
    <item>
      <title>VDE-2021-027 — Pepperl+Fuchs: WirelessHART-Gateway - Vulnerability may allow remote attackers to cause a Denial Of Service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-027</link>
      <description>&lt;p&gt;Critical vulnerabilities have been discovered in the product and in the utilized components jQuery by jQuery Team and TLS Version 1.0/1.1.&lt;/p&gt;
&lt;p&gt;The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;- denial of service
- remote code execution
- code exposure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities have been discovered in the product and in the utilized components jQuery by jQuery Team and TLS Version 1.0/1.1.&lt;/p&gt;
&lt;p&gt;The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;- denial of service
- remote code execution
- code exposure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-027</guid>
    </item>
    <item>
      <title>VDE-2025-024 — Wiesemann &amp; Theis: Multiple products from Wiesemann &amp; Theis support deprecated jQuery version</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-024</link>
      <description>&lt;p&gt;Multiple W&amp;amp;T devices are shipped with a jQuery version with a known XSS vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple W&amp;amp;T devices are shipped with a jQuery version with a known XSS vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-024</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1752 — IBM Business Automation Workflow: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1752</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Business Automation Workflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Business Automation Workflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1752</guid>
    </item>
  </channel>
</rss>
