<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:38:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10997</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10997</link>
      <description>bdu:2026-10997</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10997</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0021 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0021</link>
      <description>certfr-2025-avi-0021</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0021</guid>
    </item>
    <item>
      <title>cnvd-2020-41591</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-41591</link>
      <description>cnvd-2020-41591</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-41591</guid>
    </item>
    <item>
      <title>EUVD-2026-53955</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-53955</link>
      <description>EUVD-2026-53955</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-53955</guid>
    </item>
    <item>
      <title>fkie_cve-2019-10768</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10768</link>
      <description>&lt;p&gt;In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-10768</guid>
    </item>
    <item>
      <title>GHSA-89mq-4x47-5v83 — angular Prototype Pollution vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-89mq-4x47-5v83</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: angular&lt;/p&gt;
&lt;p&gt;Versions of `angular ` prior to 1.7.9 are vulnerable to prototype pollution. The deprecated API function `merge()` does not restrict the modification of an Object&amp;#39;s prototype in the , which may allow an attacker to add or modify an existing property that will exist on all objects.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Upgrade to version 1.7.9 or later. The function was already deprecated and upgrades are not expected to break functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: angular&lt;/p&gt;
&lt;p&gt;Versions of `angular ` prior to 1.7.9 are vulnerable to prototype pollution. The deprecated API function `merge()` does not restrict the modification of an Object&amp;#39;s prototype in the , which may allow an attacker to add or modify an existing property that will exist on all objects.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Upgrade to version 1.7.9 or later. The function was already deprecated and upgrades are not expected to break functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-89mq-4x47-5v83</guid>
    </item>
    <item>
      <title>gsd-2019-10768</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-10768</link>
      <description>gsd-2019-10768</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-10768</guid>
    </item>
    <item>
      <title>ICSA-20-133-02 — OSIsoft PI System (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-20-133-02</link>
      <description>&lt;p&gt;A local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.CVE-2020-10610 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.CVE-2020-10608 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a shared workstation or terminal server deployment.CVE-2020-10606 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.CVE-2020-10610 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.CVE-2020-10608 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a shared workstation or terminal server deployment.CVE-2020-10606 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-20-133-02</guid>
    </item>
    <item>
      <title>RHSA-2020:5568 — Red Hat Security Advisory: Red Hat Fuse 7.8.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:5568</link>
      <description>&lt;p&gt;jackson-modules-java8: DoS due to an Improper Input Validation thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol mysql-connector-java: privilege escalation in MySQL connector spring-ws: XML External Entity Injection (XXE) when receiving XML data from untrusted sources spring-batch: XML External Entity Injection (XXE) when receiving XML data from untrusted sources codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities hibernate-validator: safeHTML validator allows XSS AngularJS: Prototype pollution in merge function could result in code injection org.eclipse.paho.client.mqttv3: Improper hostname validation in the MQTT library cxf: does not restrict the number of message attachments cxf: OpenId Connect token service does not properly validate the clientId libquartz: XXE attacks via job description hibernate: SQL injection issue in Hibernate ORM batik: SSRF via &amp;#34;xlink:href&amp;#34; jetty: double release of resource can lead to information disclosure Undertow: Memory Leak in Undertow HttpOpenListener due to holding remoting connections indefinitely keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain tika: excessive memory usage in PSDParser apache-flink: JMX information disclosure vulnerability springframework: RFD attack via Content-Dispos…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-modules-java8: DoS due to an Improper Input Validation thrift: Endless loop when feed with specific input data thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol mysql-connector-java: privilege escalation in MySQL connector spring-ws: XML External Entity Injection (XXE) when receiving XML data from untrusted sources spring-batch: XML External Entity Injection (XXE) when receiving XML data from untrusted sources codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities hibernate-validator: safeHTML validator allows XSS AngularJS: Prototype pollution in merge function could result in code injection org.eclipse.paho.client.mqttv3: Improper hostname validation in the MQTT library cxf: does not restrict the number of message attachments cxf: OpenId Connect token service does not properly validate the clientId libquartz: XXE attacks via job description hibernate: SQL injection issue in Hibernate ORM batik: SSRF via &amp;#34;xlink:href&amp;#34; jetty: double release of resource can lead to information disclosure Undertow: Memory Leak in Undertow HttpOpenListener due to holding remoting connections indefinitely keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain tika: excessive memory usage in PSDParser apache-flink: JMX information disclosure vulnerability springframework: RFD attack via Content-Dispos…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:5568</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-10768</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10768</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: angular.js&lt;/p&gt;
&lt;p&gt;In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: angular.js&lt;/p&gt;
&lt;p&gt;In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10768</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0206 — Red Hat OpenStack (AngularJS): Schwachstelle ermöglicht Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0206</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenStack ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenStack ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0206</guid>
    </item>
  </channel>
</rss>
