<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:59:50 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-785 — De multiples vulnérabilités ont été découvertes dans IBM Cognos
Analytics. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-785</link>
      <description>certfr-2022-avi-785</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-785</guid>
    </item>
    <item>
      <title>cnvd-2021-37767</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-37767</link>
      <description>cnvd-2021-37767</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-37767</guid>
    </item>
    <item>
      <title>EUVD-2026-26113</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-26113</link>
      <description>EUVD-2026-26113</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-26113</guid>
    </item>
    <item>
      <title>fkie_cve-2021-28918</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28918</link>
      <description>&lt;p&gt;Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-28918</guid>
    </item>
    <item>
      <title>GHSA-4c7m-wxvm-r7gc — Improper parsing of octal bytes in netmask</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4c7m-wxvm-r7gc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: netmask&lt;/p&gt;
&lt;p&gt;Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.&lt;/p&gt;
&lt;p&gt;:exclamation: NOTE: The fix for this issue was incomplete. A subsequent fix was made in version `2.0.1` which was assigned [CVE-2021-29418 / GHSA-pch5-whg9-qr2r](https://github.com/advisories/GHSA-pch5-whg9-qr2r). For complete protection from this vulnerability an upgrade to version 2.0.1 or later is recommended.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: netmask&lt;/p&gt;
&lt;p&gt;Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.&lt;/p&gt;
&lt;p&gt;:exclamation: NOTE: The fix for this issue was incomplete. A subsequent fix was made in version `2.0.1` which was assigned [CVE-2021-29418 / GHSA-pch5-whg9-qr2r](https://github.com/advisories/GHSA-pch5-whg9-qr2r). For complete protection from this vulnerability an upgrade to version 2.0.1 or later is recommended.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4c7m-wxvm-r7gc</guid>
    </item>
    <item>
      <title>gsd-2021-28918</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-28918</link>
      <description>gsd-2021-28918</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-28918</guid>
    </item>
    <item>
      <title>RHSA-2021:1499 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.2.3 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1499</link>
      <description>&lt;p&gt;nodejs-glob-parent: Regular expression denial of service nodejs-underscore: Arbitrary code execution via the template function nodejs-is-svg: ReDoS via malicious string nodejs-netmask: improper input validation of octal input data nodejs-netmask: incorrectly parses an IP address that has octal integer with invalid character&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-glob-parent: Regular expression denial of service nodejs-underscore: Arbitrary code execution via the template function nodejs-is-svg: ReDoS via malicious string nodejs-netmask: improper input validation of octal input data nodejs-netmask: incorrectly parses an IP address that has octal integer with invalid character&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1499</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1354 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354</guid>
    </item>
  </channel>
</rss>
