<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:58:47 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03176</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03176</link>
      <description>bdu:2023-03176</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03176</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0630 — De multiples vulnérabilités ont été découvertes dans IBM QRadar. Certaines d'entre elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0630</link>
      <description>certfr-2024-avi-0630</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0630</guid>
    </item>
    <item>
      <title>EUVD-2026-262477</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262477</link>
      <description>EUVD-2026-262477</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262477</guid>
    </item>
    <item>
      <title>fkie_cve-2023-0842</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0842</link>
      <description>&lt;p&gt;xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-0842</guid>
    </item>
    <item>
      <title>GHSA-776f-qx25-q3cc — xml2js is vulnerable to prototype pollution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-776f-qx25-q3cc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: xml2js&lt;/p&gt;
&lt;p&gt;xml2js versions before 0.5.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the `__proto__` property to be edited.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: xml2js&lt;/p&gt;
&lt;p&gt;xml2js versions before 0.5.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the `__proto__` property to be edited.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-776f-qx25-q3cc</guid>
    </item>
    <item>
      <title>gsd-2023-0842</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-0842</link>
      <description>gsd-2023-0842</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-0842</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-0842</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0842</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-xml2js, Ubuntu:18.04:LTS: node-xml2js, Ubuntu:20.04:LTS: node-xml2js, Ubuntu:22.04:LTS: node-xml2js, Ubuntu:24.04:LTS: node-xml2js, Ubuntu:25.10: node-xml2js, Ubuntu:26.04:LTS: node-xml2js&lt;/p&gt;
&lt;p&gt;xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-xml2js, Ubuntu:18.04:LTS: node-xml2js, Ubuntu:20.04:LTS: node-xml2js, Ubuntu:22.04:LTS: node-xml2js, Ubuntu:24.04:LTS: node-xml2js, Ubuntu:25.10: node-xml2js, Ubuntu:26.04:LTS: node-xml2js&lt;/p&gt;
&lt;p&gt;xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0842</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0180 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</guid>
    </item>
  </channel>
</rss>
