<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:56:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-06615</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06615</link>
      <description>bdu:2022-06615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06615</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0869 — De multiples vulnérabilités ont été découvertes dans Zimbra &lt;span
id="Zimbra_Collaboration_Daffodil_10.0.5_Patch_Releas…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0869</link>
      <description>certfr-2023-avi-0869</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0869</guid>
    </item>
    <item>
      <title>EUVD-2026-169899</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-169899</link>
      <description>EUVD-2026-169899</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-169899</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7746</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7746</link>
      <description>&lt;p&gt;This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7746</guid>
    </item>
    <item>
      <title>GHSA-h68q-55jf-x68w — Prototype pollution in chart.js</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h68q-55jf-x68w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: chart.js&lt;/p&gt;
&lt;p&gt;This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: chart.js&lt;/p&gt;
&lt;p&gt;This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h68q-55jf-x68w</guid>
    </item>
    <item>
      <title>gsd-2020-7746</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7746</link>
      <description>gsd-2020-7746</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7746</guid>
    </item>
    <item>
      <title>jvndb-2026-033235</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-033235</link>
      <description>&lt;p&gt;CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/79.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/78.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/548.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/1395.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://www.cve.org/CVERecord?id=CVE-2020-7746&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/434.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/79.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/787.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/352.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/256.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/306.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/121.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/522.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/306.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/95.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Cross-site scripting (CWE-79) - CVE-2026-82773, CVE-2026-82776, CVE-2026-82788&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;OS command injection (CWE-78) - CVE-2026-82774, CVE-2026-82777, CVE-2026-82779&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Exposure of information through directory listing (CWE-548…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CONPROSYS series provided by Contec Co., Ltd. contains multiple vulnerabilities listed below.&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/79.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/78.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/548.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/1395.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://www.cve.org/CVERecord?id=CVE-2020-7746&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/434.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/79.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/787.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/352.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/256.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/306.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/121.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/522.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/306.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/95.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Cross-site scripting (CWE-79) - CVE-2026-82773, CVE-2026-82776, CVE-2026-82788&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;OS command injection (CWE-78) - CVE-2026-82774, CVE-2026-82777, CVE-2026-82779&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Exposure of information through directory listing (CWE-548…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-033235</guid>
    </item>
    <item>
      <title>RHSA-2022:6813 — Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6813</link>
      <description>&lt;p&gt;chart.js: prototype pollution jackson-databind: denial of service via a large depth of nested objects immer: type confusion vulnerability can lead to a bypass of CVE-2020-28477 minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor parse-url: Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor drools: unsafe data deserialization in StreamUtils eventsource: Exposure of Sensitive Information Business-central: Possible XML External Entity Injection attack mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes xerces-j2: infinite loop when handling specially crafted XML document payloads artemis-commons: Apache ActiveMQ Artemis DoS node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery Moment.js: Path traversal  in moment.locale postgresql-jdbc: Arbitrary File Write Vulnerability moment: inefficient parsing algorithm resulting in DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;chart.js: prototype pollution jackson-databind: denial of service via a large depth of nested objects immer: type confusion vulnerability can lead to a bypass of CVE-2020-28477 minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor parse-url: Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor drools: unsafe data deserialization in StreamUtils eventsource: Exposure of Sensitive Information Business-central: Possible XML External Entity Injection attack mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors jdbc-postgresql: Unchecked Class Instantiation when providing Plugin Classes xerces-j2: infinite loop when handling specially crafted XML document payloads artemis-commons: Apache ActiveMQ Artemis DoS node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery Moment.js: Path traversal  in moment.locale postgresql-jdbc: Arbitrary File Write Vulnerability moment: inefficient parsing algorithm resulting in DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6813</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-7746</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7746</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-chart.js&lt;/p&gt;
&lt;p&gt;This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-chart.js&lt;/p&gt;
&lt;p&gt;This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7746</guid>
    </item>
  </channel>
</rss>
