<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:51:40 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-38066</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-38066</link>
      <description>cnvd-2020-38066</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-38066</guid>
    </item>
    <item>
      <title>EUVD-2026-37667</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-37667</link>
      <description>EUVD-2026-37667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-37667</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7013</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7013</link>
      <description>&lt;p&gt;Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7013</guid>
    </item>
    <item>
      <title>GHSA-7j4x-vm2f-rhf2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7j4x-vm2f-rhf2</link>
      <description>&lt;p&gt;Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7j4x-vm2f-rhf2</guid>
    </item>
    <item>
      <title>gsd-2020-7013</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7013</link>
      <description>gsd-2020-7013</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7013</guid>
    </item>
    <item>
      <title>RHSA-2020:4298 — Red Hat Security Advisory: OpenShift Container Platform 4.6.1 image security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4298</link>
      <description>&lt;p&gt;SSL/TLS: CBC padding timing attack (lucky-13) grafana: XSS vulnerability via a column style on the &amp;#34;Dashboard &amp;gt; Table Panel&amp;#34; screen jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06) nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser nodejs-lodash: prototype pollution in zipObjectDeep function kubernetes: compromised node could escalate to cluster level privileges golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic openshift/console: text injection on error page via crafted url kibana: X-Frame-Option not set by default might lead to clickjacking jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods grafana: stored XSS grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash open…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SSL/TLS: CBC padding timing attack (lucky-13) grafana: XSS vulnerability via a column style on the &amp;#34;Dashboard &amp;gt; Table Panel&amp;#34; screen jquery: Prototype pollution in object&amp;#39;s prototype leading to denial of service, remote code execution, or property injection npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06) nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser nodejs-lodash: prototype pollution in zipObjectDeep function kubernetes: compromised node could escalate to cluster level privileges golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic openshift/console: text injection on error page via crafted url kibana: X-Frame-Option not set by default might lead to clickjacking jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &amp;lt;option&amp;gt; tag in HTML passed to DOM manipulation methods grafana: stored XSS grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash open…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4298</guid>
    </item>
  </channel>
</rss>
