<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:20:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10996</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10996</link>
      <description>bdu:2026-10996</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10996</guid>
    </item>
    <item>
      <title>certfr-2022-avi-351 — De multiples vulnérabilités ont été découvertes dans les logiciels
Juniper . Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-351</link>
      <description>certfr-2022-avi-351</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-351</guid>
    </item>
    <item>
      <title>EUVD-2026-27543</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-27543</link>
      <description>EUVD-2026-27543</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-27543</guid>
    </item>
    <item>
      <title>fkie_cve-2021-31597</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-31597</link>
      <description>&lt;p&gt;The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-31597</guid>
    </item>
    <item>
      <title>GHSA-72mh-269x-7mh5 — Improper Certificate Validation in xmlhttprequest-ssl</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-72mh-269x-7mh5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: xmlhttprequest-ssl&lt;/p&gt;
&lt;p&gt;The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: xmlhttprequest-ssl&lt;/p&gt;
&lt;p&gt;The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-72mh-269x-7mh5</guid>
    </item>
    <item>
      <title>gsd-2021-31597</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-31597</link>
      <description>gsd-2021-31597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-31597</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-31597</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-31597</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-xmlhttprequest-ssl, Ubuntu:20.04:LTS: node-xmlhttprequest-ssl&lt;/p&gt;
&lt;p&gt;The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-xmlhttprequest-ssl, Ubuntu:20.04:LTS: node-xmlhttprequest-ssl&lt;/p&gt;
&lt;p&gt;The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-31597</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1229 — Atlassian Bamboo, Bitbucket, Confluence, Jira: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1229</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1229</guid>
    </item>
  </channel>
</rss>
