<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 13:36:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-166229</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-166229</link>
      <description>EUVD-2026-166229</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-166229</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7677</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7677</link>
      <description>&lt;p&gt;This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7677</guid>
    </item>
    <item>
      <title>GHSA-29xr-v42j-r956 — thenify before 3.3.1 made use of unsafe calls to `eval`.</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-29xr-v42j-r956</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: thenify, Maven: org.webjars.npm:thenify&lt;/p&gt;
&lt;p&gt;Versions of thenify prior to 3.3.1 made use of unsafe calls to `eval`. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to `eval`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: thenify, Maven: org.webjars.npm:thenify&lt;/p&gt;
&lt;p&gt;Versions of thenify prior to 3.3.1 made use of unsafe calls to `eval`. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to `eval`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-29xr-v42j-r956</guid>
    </item>
    <item>
      <title>gsd-2020-7677</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7677</link>
      <description>gsd-2020-7677</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7677</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-7677</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7677</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-thenify, Ubuntu:20.04:LTS: node-thenify&lt;/p&gt;
&lt;p&gt;This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-thenify, Ubuntu:20.04:LTS: node-thenify&lt;/p&gt;
&lt;p&gt;This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7677</guid>
    </item>
  </channel>
</rss>
