<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:22:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-05598</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05598</link>
      <description>bdu:2022-05598</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05598</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0597 — De multiples vulnérabilités ont été découvertes dans&lt;span
class="textit"&gt; IBM Cognos Analytics&lt;/span&gt;. Certaines d'entr…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0597</link>
      <description>certfr-2023-avi-0597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0597</guid>
    </item>
    <item>
      <title>cnvd-2022-68930</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-68930</link>
      <description>cnvd-2022-68930</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-68930</guid>
    </item>
    <item>
      <title>EUVD-2026-232638</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232638</link>
      <description>EUVD-2026-232638</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232638</guid>
    </item>
    <item>
      <title>fkie_cve-2022-36067</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36067</link>
      <description>&lt;p&gt;vm2 is a sandbox that can run untrusted code with whitelisted Node&amp;#39;s built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is a sandbox that can run untrusted code with whitelisted Node&amp;#39;s built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-36067</guid>
    </item>
    <item>
      <title>GHSA-mrgp-mrhc-5jrq — vm2 vulnerable to Sandbox Escape resulting in Remote Code Execution on host</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mrgp-mrhc-5jrq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Impact
A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability was patched in the release of version `3.9.11` of `vm2`&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
Github Issue - https://github.com/patriksimek/vm2/issues/467
The file that was patched - https://github.com/patriksimek/vm2/blob/master/lib/setup-sandbox.js#L71
The commit with the patch - https://github.com/patriksimek/vm2/commit/d9a7f3cc995d3d861e1380eafb886cb3c5e2b873#diff-b1a515a627d820118e76d0e323fe2f0589ed50a1eacb490f6c3278fe3698f164&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [VM2](https://github.com/patriksimek/vm2)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Impact
A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability was patched in the release of version `3.9.11` of `vm2`&lt;/p&gt;
&lt;p&gt;### Workarounds
None.&lt;/p&gt;
&lt;p&gt;### References
Github Issue - https://github.com/patriksimek/vm2/issues/467
The file that was patched - https://github.com/patriksimek/vm2/blob/master/lib/setup-sandbox.js#L71
The commit with the patch - https://github.com/patriksimek/vm2/commit/d9a7f3cc995d3d861e1380eafb886cb3c5e2b873#diff-b1a515a627d820118e76d0e323fe2f0589ed50a1eacb490f6c3278fe3698f164&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [VM2](https://github.com/patriksimek/vm2)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mrgp-mrhc-5jrq</guid>
    </item>
    <item>
      <title>gsd-2022-36067</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-36067</link>
      <description>gsd-2022-36067</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-36067</guid>
    </item>
    <item>
      <title>RHSA-2022:6422 — Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.0.2 security and bug fixes</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6422</link>
      <description>&lt;p&gt;moment: inefficient parsing algorithm resulting in DoS vm2: Sandbox Escape in vm2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;moment: inefficient parsing algorithm resulting in DoS vm2: Sandbox Escape in vm2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6422</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1004 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1004</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um aus der Sandbox auszubrechen und beliebigen Code im Host-Kontext auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um aus der Sandbox auszubrechen und beliebigen Code im Host-Kontext auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1004</guid>
    </item>
  </channel>
</rss>
