<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:25:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00718</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00718</link>
      <description>bdu:2026-00718</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00718</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1119 — De multiples vulnérabilités ont été découvertes dans Tenable Nessus
Network Monitor. Elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1119</link>
      <description>certfr-2022-avi-1119</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1119</guid>
    </item>
    <item>
      <title>EUVD-2026-258339</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258339</link>
      <description>EUVD-2026-258339</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258339</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24785</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24785</link>
      <description>&lt;p&gt;Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24785</guid>
    </item>
    <item>
      <title>GHSA-8hfj-j24r-96c4 — Path Traversal: 'dir/../../filename' in moment.locale</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8hfj-j24r-96c4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: moment, NuGet: Moment.js&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg `fr` is directly used to switch moment locale.&lt;/p&gt;
&lt;p&gt;### Patches
This problem is patched in 2.29.2, and the patch can be applied to all affected versions (from 1.0.1 up until 2.29.1, inclusive).&lt;/p&gt;
&lt;p&gt;### Workarounds
Sanitize user-provided locale name before passing it to moment.js.&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [moment repo](https://github.com/moment/moment)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: moment, NuGet: Moment.js&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg `fr` is directly used to switch moment locale.&lt;/p&gt;
&lt;p&gt;### Patches
This problem is patched in 2.29.2, and the patch can be applied to all affected versions (from 1.0.1 up until 2.29.1, inclusive).&lt;/p&gt;
&lt;p&gt;### Workarounds
Sanitize user-provided locale name before passing it to moment.js.&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [moment repo](https://github.com/moment/moment)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8hfj-j24r-96c4</guid>
    </item>
    <item>
      <title>gsd-2022-24785</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24785</link>
      <description>gsd-2022-24785</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24785</guid>
    </item>
    <item>
      <title>RHSA-2022:1681 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.4 security updates and bug fixes</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1681</link>
      <description>&lt;p&gt;vm2: vulnerable to Sandbox Bypass golang.org/x/crypto: empty plaintext packet causes panic follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor node-fetch: exposure of sensitive information to an unauthorized actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak urijs: Authorization Bypass Through User-Controlled Key cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor nconf: Prototype pollution in memory store nats-server: misusing the &amp;#34;dynamically provisioned sandbox accounts&amp;#34; feature  authenticated user can obtain the privileges of the System account urijs: Leading white space bypasses protocol validation node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery node-forge: Signature verification leniency in checking `DigestInfo` structure Moment.js: Path traversal  in moment.locale&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2: vulnerable to Sandbox Bypass golang.org/x/crypto: empty plaintext packet causes panic follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor node-fetch: exposure of sensitive information to an unauthorized actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak urijs: Authorization Bypass Through User-Controlled Key cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor nconf: Prototype pollution in memory store nats-server: misusing the &amp;#34;dynamically provisioned sandbox accounts&amp;#34; feature  authenticated user can obtain the privileges of the System account urijs: Leading white space bypasses protocol validation node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery node-forge: Signature verification leniency in checking `DigestInfo` structure Moment.js: Path traversal  in moment.locale&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1681</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-24785</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24785</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: nikola, Ubuntu:Pro:16.04:LTS: node-moment, Ubuntu:18.04:LTS: node-moment, Ubuntu:20.04:LTS: node-moment, Ubuntu:22.04:LTS: node-moment&lt;/p&gt;
&lt;p&gt;Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: nikola, Ubuntu:Pro:16.04:LTS: node-moment, Ubuntu:18.04:LTS: node-moment, Ubuntu:20.04:LTS: node-moment, Ubuntu:22.04:LTS: node-moment&lt;/p&gt;
&lt;p&gt;Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24785</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0288 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0288</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen, einen nicht näher spezifizierten Angriff durchzuführen, vertrauliche Informationen offenzulegen und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen, einen nicht näher spezifizierten Angriff durchzuführen, vertrauliche Informationen offenzulegen und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0288</guid>
    </item>
  </channel>
</rss>
