<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:42:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-05431</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-05431</link>
      <description>bdu:2021-05431</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-05431</guid>
    </item>
    <item>
      <title>certfr-2021-avi-671 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect Plus. Elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-671</link>
      <description>certfr-2021-avi-671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-671</guid>
    </item>
    <item>
      <title>EUVD-2026-22217</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-22217</link>
      <description>EUVD-2026-22217</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-22217</guid>
    </item>
    <item>
      <title>fkie_cve-2021-21388</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21388</link>
      <description>&lt;p&gt;systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has been fixed with a parameter check on user input. Please upgrade to version &amp;gt;= 5.6.4. If you cannot upgrade, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() and other commands. Only allow strings, reject any arrays. String sanitation works as expected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has been fixed with a parameter check on user input. Please upgrade to version &amp;gt;= 5.6.4. If you cannot upgrade, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() and other commands. Only allow strings, reject any arrays. String sanitation works as expected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-21388</guid>
    </item>
    <item>
      <title>GHSA-jff2-qjw8-5476 — Command Injection Vulnerability in systeminformation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jff2-qjw8-5476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: systeminformation&lt;/p&gt;
&lt;p&gt;### Impact
command injection vulnerability&lt;/p&gt;
&lt;p&gt;### Patches
Problem was fixed with a parameter check. Please upgrade to version &amp;gt;= 5.6.4&lt;/p&gt;
&lt;p&gt;### Workarounds
If you cannot upgrade, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: systeminformation&lt;/p&gt;
&lt;p&gt;### Impact
command injection vulnerability&lt;/p&gt;
&lt;p&gt;### Patches
Problem was fixed with a parameter check. Please upgrade to version &amp;gt;= 5.6.4&lt;/p&gt;
&lt;p&gt;### Workarounds
If you cannot upgrade, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jff2-qjw8-5476</guid>
    </item>
    <item>
      <title>gsd-2021-21388</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-21388</link>
      <description>gsd-2021-21388</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-21388</guid>
    </item>
  </channel>
</rss>
