<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:52:42 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:1846 — Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:1846</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bind-dyndb-ldap, AlmaLinux:8: custodia, AlmaLinux:8: opendnssec, AlmaLinux:8: python3-custodia, AlmaLinux:8: python3-jwcrypto, AlmaLinux:8: python3-kdcproxy, AlmaLinux:8: python3-pyusb, AlmaLinux:8: python3-qrcode, AlmaLinux:8: python3-qrcode-core, AlmaLinux:8: python3-yubico and 2 more&lt;/p&gt;
&lt;p&gt;AlmaLinux Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* jquery: Passing HTML containing &amp;lt;option&amp;gt; elements to manipulation methods could result in untrusted code execution (CVE-2020-11023)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bind-dyndb-ldap, AlmaLinux:8: custodia, AlmaLinux:8: opendnssec, AlmaLinux:8: python3-custodia, AlmaLinux:8: python3-jwcrypto, AlmaLinux:8: python3-kdcproxy, AlmaLinux:8: python3-pyusb, AlmaLinux:8: python3-qrcode, AlmaLinux:8: python3-qrcode-core, AlmaLinux:8: python3-yubico and 2 more&lt;/p&gt;
&lt;p&gt;AlmaLinux Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* jquery: Passing HTML containing &amp;lt;option&amp;gt; elements to manipulation methods could result in untrusted code execution (CVE-2020-11023)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:1846</guid>
    </item>
    <item>
      <title>bdu:2020-04949</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-04949</link>
      <description>bdu:2020-04949</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-04949</guid>
    </item>
    <item>
      <title>BIT-drupal-2020-11023 — Potential XSS vulnerability in jQuery</title>
      <link>https://cve.radiocsirt.org/vuln/bit-drupal-2020-11023</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: drupal&lt;/p&gt;
&lt;p&gt;In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing &amp;lt;option&amp;gt; elements from untrusted sources - even after sanitizing it - to one of jQuery&amp;#39;s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: drupal&lt;/p&gt;
&lt;p&gt;In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing &amp;lt;option&amp;gt; elements from untrusted sources - even after sanitizing it - to one of jQuery&amp;#39;s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-drupal-2020-11023</guid>
    </item>
    <item>
      <title>certfr-2020-avi-310 — De multiples vulnérabilités ont été découvertes dans Drupal. Elles
permettent à un attaquant de provoquer un contournem…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-310</link>
      <description>certfr-2020-avi-310</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-310</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-DL38300 — In jQuery versions greater than or equal to 1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-dl38300</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cacti, CleanStart: drupal7&lt;/p&gt;
&lt;p&gt;CVE-2020-11023 affects multiple packages. In jQuery versions greater than or equal to 1. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cacti, CleanStart: drupal7&lt;/p&gt;
&lt;p&gt;CVE-2020-11023 affects multiple packages. In jQuery versions greater than or equal to 1. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-dl38300</guid>
    </item>
    <item>
      <title>cnvd-2020-27491</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-27491</link>
      <description>cnvd-2020-27491</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-27491</guid>
    </item>
    <item>
      <title>ESSA-2025:2436 — Moderate: tbb security update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2025:2436</link>
      <description>&lt;p&gt;Moderate: tbb security update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Moderate: tbb security update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2025:2436</guid>
    </item>
    <item>
      <title>EUVD-2026-256107</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-256107</link>
      <description>EUVD-2026-256107</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-256107</guid>
    </item>
    <item>
      <title>fkie_cve-2020-11023</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11023</link>
      <description>&lt;p&gt;In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing &amp;lt;option&amp;gt; elements from untrusted sources - even after sanitizing it - to one of jQuery&amp;#39;s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing &amp;lt;option&amp;gt; elements from untrusted sources - even after sanitizing it - to one of jQuery&amp;#39;s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-11023</guid>
    </item>
    <item>
      <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202601</link>
      <description>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202601</guid>
    </item>
    <item>
      <title>GHSA-jpcq-cgw6-v4j6 — Potential XSS vulnerability in jQuery</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jpcq-cgw6-v4j6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jquery, RubyGems: jquery-rails, NuGet: jQuery, Maven: org.webjars.npm:jquery, Packagist: components/jquery&lt;/p&gt;
&lt;p&gt;### Impact
Passing HTML containing `&amp;lt;option&amp;gt;` elements from untrusted sources - even after sanitizing them - to one of jQuery&amp;#39;s DOM manipulation methods (i.e. `.html()`, `.append()`, and others) may execute untrusted code.&lt;/p&gt;
&lt;p&gt;### Patches
This problem is patched in jQuery 3.5.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
To workaround this issue without upgrading, use [DOMPurify](https://github.com/cure53/DOMPurify) with its `SAFE_FOR_JQUERY` option to sanitize the HTML string before passing it to a jQuery method.&lt;/p&gt;
&lt;p&gt;### References
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery repo](https://github.com/jquery/jquery/issues). If you don&amp;#39;t find an answer, open a new issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jquery, RubyGems: jquery-rails, NuGet: jQuery, Maven: org.webjars.npm:jquery, Packagist: components/jquery&lt;/p&gt;
&lt;p&gt;### Impact
Passing HTML containing `&amp;lt;option&amp;gt;` elements from untrusted sources - even after sanitizing them - to one of jQuery&amp;#39;s DOM manipulation methods (i.e. `.html()`, `.append()`, and others) may execute untrusted code.&lt;/p&gt;
&lt;p&gt;### Patches
This problem is patched in jQuery 3.5.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
To workaround this issue without upgrading, use [DOMPurify](https://github.com/cure53/DOMPurify) with its `SAFE_FOR_JQUERY` option to sanitize the HTML string before passing it to a jQuery method.&lt;/p&gt;
&lt;p&gt;### References
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery repo](https://github.com/jquery/jquery/issues). If you don&amp;#39;t find an answer, open a new issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jpcq-cgw6-v4j6</guid>
    </item>
    <item>
      <title>gsd-2020-11023</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-11023</link>
      <description>gsd-2020-11023</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-11023</guid>
    </item>
    <item>
      <title>ICSA-21-306-01 — Sensormatic Electronics VideoEdge</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-306-01</link>
      <description>&lt;p&gt;A vulnerability in the JQuery web user interface (UI) component could allow a webpage to be altered before it is served to users.CVE-2020-11023 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the JQuery web user interface (UI) component could allow a webpage to be altered before it is served to users.CVE-2020-11023 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-306-01</guid>
    </item>
    <item>
      <title>RHBA-2025:1079 — Red Hat Bug Fix Advisory: Red Hat Quay v3.13.4 bug fix release</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:1079</link>
      <description>&lt;p&gt;jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:1079</guid>
    </item>
    <item>
      <title>SEVD-2025-189-02 — System Monitor Application in Harmony and Pro-face PS5000 Legacy Industrial PCs</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2025-189-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in its System Monitor application of Harmony Industrial PC and &#13;
Pro-face PS5000 trusted Legacy industrial PC series products.&#13;
The Harmony Industrial PC Series and Pro-face PS5000 legacy industrial PC Series are iPCs which &#13;
incorporate slim, flexible and durable design allowing each customer to configure their iPC based on their &#13;
individual application needs. These products offer flexible connectivity to a range of devices and designs. &#13;
Failure to apply the remediations provided below may risk untrusted code execution which could result in &#13;
operational failures.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in its System Monitor application of Harmony Industrial PC and &#13;
Pro-face PS5000 trusted Legacy industrial PC series products.&#13;
The Harmony Industrial PC Series and Pro-face PS5000 legacy industrial PC Series are iPCs which &#13;
incorporate slim, flexible and durable design allowing each customer to configure their iPC based on their &#13;
individual application needs. These products offer flexible connectivity to a range of devices and designs. &#13;
Failure to apply the remediations provided below may risk untrusted code execution which could result in &#13;
operational failures.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2025-189-02</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-11023</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11023</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: drupal7, Ubuntu:Pro:16.04:LTS: drupal7, Ubuntu:Pro:18.04:LTS: jquery, Ubuntu:20.04:LTS: jquery&lt;/p&gt;
&lt;p&gt;In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing &amp;lt;option&amp;gt; elements from untrusted sources - even after sanitizing it - to one of jQuery&amp;#39;s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: drupal7, Ubuntu:Pro:16.04:LTS: drupal7, Ubuntu:Pro:18.04:LTS: jquery, Ubuntu:20.04:LTS: jquery&lt;/p&gt;
&lt;p&gt;In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing &amp;lt;option&amp;gt; elements from untrusted sources - even after sanitizing it - to one of jQuery&amp;#39;s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11023</guid>
    </item>
    <item>
      <title>VDE-2021-027 — Pepperl+Fuchs: WirelessHART-Gateway - Vulnerability may allow remote attackers to cause a Denial Of Service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-027</link>
      <description>&lt;p&gt;Critical vulnerabilities have been discovered in the product and in the utilized components jQuery by jQuery Team and TLS Version 1.0/1.1.&lt;/p&gt;
&lt;p&gt;The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;- denial of service
- remote code execution
- code exposure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities have been discovered in the product and in the utilized components jQuery by jQuery Team and TLS Version 1.0/1.1.&lt;/p&gt;
&lt;p&gt;The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;- denial of service
- remote code execution
- code exposure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-027</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1347 — jQuery: Mehrere Schwachstellen ermöglichen Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1347</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in jQuery ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in jQuery ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1347</guid>
    </item>
  </channel>
</rss>
