<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:16:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-02877</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-02877</link>
      <description>bdu:2021-02877</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-02877</guid>
    </item>
    <item>
      <title>certfr-2021-avi-671 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect Plus. Elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-671</link>
      <description>certfr-2021-avi-671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-671</guid>
    </item>
    <item>
      <title>EUVD-2026-169539</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-169539</link>
      <description>EUVD-2026-169539</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-169539</guid>
    </item>
    <item>
      <title>fkie_cve-2021-23337</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-23337</link>
      <description>&lt;p&gt;Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-23337</guid>
    </item>
    <item>
      <title>GHSA-35jh-r3h4-6jhm — Command Injection in lodash</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-35jh-r3h4-6jhm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: lodash, npm: lodash-es, npm: lodash.template, npm: lodash-template, RubyGems: lodash-rails&lt;/p&gt;
&lt;p&gt;`lodash` versions prior to 4.17.21 are vulnerable to Command Injection via the template function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: lodash, npm: lodash-es, npm: lodash.template, npm: lodash-template, RubyGems: lodash-rails&lt;/p&gt;
&lt;p&gt;`lodash` versions prior to 4.17.21 are vulnerable to Command Injection via the template function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-35jh-r3h4-6jhm</guid>
    </item>
    <item>
      <title>gsd-2021-23337</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-23337</link>
      <description>gsd-2021-23337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-23337</guid>
    </item>
    <item>
      <title>ICSA-22-258-05 — Siemens SINEC INS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-258-05</link>
      <description>&lt;p&gt;The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. axios is vulnerable to Inefficient Regular Expression Complexity There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multip…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. axios is vulnerable to Inefficient Regular Expression Complexity There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multip…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-258-05</guid>
    </item>
    <item>
      <title>RHSA-2021:1168 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.2.2 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1168</link>
      <description>&lt;p&gt;golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag go-slug: partial protection against zip slip attacks fastify-reply-from: crafted URL allows prefix scape of the proxied backend service fastify-http-proxy: crafted URL allows prefix scape of the proxied backend service nodejs-lodash: command injection via template openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag go-slug: partial protection against zip slip attacks fastify-reply-from: crafted URL allows prefix scape of the proxied backend service fastify-http-proxy: crafted URL allows prefix scape of the proxied backend service nodejs-lodash: command injection via template openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1168</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-23337</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23337</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: node-lodash, Ubuntu:Pro:18.04:LTS: node-lodash, Ubuntu:Pro:20.04:LTS: node-lodash&lt;/p&gt;
&lt;p&gt;Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: node-lodash, Ubuntu:Pro:18.04:LTS: node-lodash, Ubuntu:Pro:20.04:LTS: node-lodash&lt;/p&gt;
&lt;p&gt;Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23337</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1375 — JFrog Artifactory: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</guid>
    </item>
  </channel>
</rss>
