<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:03:11 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-02902</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-02902</link>
      <description>bdu:2021-02902</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-02902</guid>
    </item>
    <item>
      <title>certfr-2022-avi-278 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
discover. Certaines d'entre elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</link>
      <description>certfr-2022-avi-278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</guid>
    </item>
    <item>
      <title>cnvd-2020-53801</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-53801</link>
      <description>cnvd-2020-53801</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-53801</guid>
    </item>
    <item>
      <title>EUVD-2026-38081</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-38081</link>
      <description>EUVD-2026-38081</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-38081</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7660</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7660</link>
      <description>&lt;p&gt;serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function &amp;#34;deleteFunctions&amp;#34; within &amp;#34;index.js&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function &amp;#34;deleteFunctions&amp;#34; within &amp;#34;index.js&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7660</guid>
    </item>
    <item>
      <title>GHSA-hxcc-f52p-wc94 — Insecure serialization leading to RCE in serialize-javascript</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hxcc-f52p-wc94</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: serialize-javascript&lt;/p&gt;
&lt;p&gt;serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function &amp;#34;deleteFunctions&amp;#34; within &amp;#34;index.js&amp;#34;.&lt;/p&gt;
&lt;p&gt;An object such as `{&amp;#34;foo&amp;#34;: /1&amp;#34;/, &amp;#34;bar&amp;#34;: &amp;#34;a\&amp;#34;@__R-&amp;lt;UID&amp;gt;-0__@&amp;#34;}` was serialized as `{&amp;#34;foo&amp;#34;: /1&amp;#34;/, &amp;#34;bar&amp;#34;: &amp;#34;a\/1&amp;#34;/}`, which allows an attacker to escape the `bar` key. This requires the attacker to control the values of both `foo` and `bar` and guess the value of `&amp;lt;UID&amp;gt;`. The UID has a keyspace of approximately 4 billion making it a realistic network attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: serialize-javascript&lt;/p&gt;
&lt;p&gt;serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function &amp;#34;deleteFunctions&amp;#34; within &amp;#34;index.js&amp;#34;.&lt;/p&gt;
&lt;p&gt;An object such as `{&amp;#34;foo&amp;#34;: /1&amp;#34;/, &amp;#34;bar&amp;#34;: &amp;#34;a\&amp;#34;@__R-&amp;lt;UID&amp;gt;-0__@&amp;#34;}` was serialized as `{&amp;#34;foo&amp;#34;: /1&amp;#34;/, &amp;#34;bar&amp;#34;: &amp;#34;a\/1&amp;#34;/}`, which allows an attacker to escape the `bar` key. This requires the attacker to control the values of both `foo` and `bar` and guess the value of `&amp;lt;UID&amp;gt;`. The UID has a keyspace of approximately 4 billion making it a realistic network attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hxcc-f52p-wc94</guid>
    </item>
    <item>
      <title>gsd-2020-7660</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7660</link>
      <description>gsd-2020-7660</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7660</guid>
    </item>
    <item>
      <title>RHSA-2020:2796 — Red Hat Security Advisory: Red Hat OpenShift Service Mesh servicemesh-grafana security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:2796</link>
      <description>&lt;p&gt;kubernetes: YAML parsing vulnerable to &amp;#34;Billion Laughs&amp;#34; attack, allowing for remote denial of service npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions npm-serialize-javascript: allows remote attackers to inject arbitrary code via the function deleteFunctions within index.js npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL grafana: XSS via the OpenTSDB datasource&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kubernetes: YAML parsing vulnerable to &amp;#34;Billion Laughs&amp;#34; attack, allowing for remote denial of service npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions npm-serialize-javascript: allows remote attackers to inject arbitrary code via the function deleteFunctions within index.js npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL grafana: XSS via the OpenTSDB datasource&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:2796</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1591 — Juniper JUNOS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1591</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Juniper JUNOS ausnutzen, um einen Denial of Service  zu verursachen, Informationen offenzulegen, Privilegien zu erweitern und Sicherheitsmechanismen inklusive zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Juniper JUNOS ausnutzen, um einen Denial of Service  zu verursachen, Informationen offenzulegen, Privilegien zu erweitern und Sicherheitsmechanismen inklusive zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1591</guid>
    </item>
  </channel>
</rss>
