<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:26:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-01322</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01322</link>
      <description>bdu:2021-01322</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01322</guid>
    </item>
    <item>
      <title>certfr-2021-avi-700 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-700</link>
      <description>certfr-2021-avi-700</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-700</guid>
    </item>
    <item>
      <title>EUVD-2026-36460</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-36460</link>
      <description>EUVD-2026-36460</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-36460</guid>
    </item>
    <item>
      <title>fkie_cve-2020-5259</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-5259</link>
      <description>&lt;p&gt;In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-5259</guid>
    </item>
    <item>
      <title>GHSA-3hw5-q855-g6cw — Prototype Pollution in Dojox</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3hw5-q855-g6cw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dojox&lt;/p&gt;
&lt;p&gt;The Dojox jQuery wrapper `jqMix` mixin method is vulnerable to Prototype Pollution.&lt;/p&gt;
&lt;p&gt;Affected Area:
```
//https://github.com/dojo/dojox/blob/master/jq.js#L442
		var tobj = {};
		for(var x in props){
			// the &amp;#34;tobj&amp;#34; condition avoid copying properties in &amp;#34;props&amp;#34;
			// inherited from Object.prototype.  For example, if obj has a custom
			// toString() method, don&amp;#39;t overwrite it with the toString() method
			// that props inherited from Object.prototype
			if((tobj[x] === undefined || tobj[x] != props[x]) &amp;amp;&amp;amp; props[x] !== undefined &amp;amp;&amp;amp; obj != props[x]){
				if(dojo.isObject(obj[x]) &amp;amp;&amp;amp; dojo.isObject(props[x])){
					if(dojo.isArray(props[x])){
						obj[x] = props[x];
					}else{
						obj[x] = jqMix(obj[x], props[x]);
					}
				}else{
					obj[x] = props[x];
				}
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dojox&lt;/p&gt;
&lt;p&gt;The Dojox jQuery wrapper `jqMix` mixin method is vulnerable to Prototype Pollution.&lt;/p&gt;
&lt;p&gt;Affected Area:
```
//https://github.com/dojo/dojox/blob/master/jq.js#L442
		var tobj = {};
		for(var x in props){
			// the &amp;#34;tobj&amp;#34; condition avoid copying properties in &amp;#34;props&amp;#34;
			// inherited from Object.prototype.  For example, if obj has a custom
			// toString() method, don&amp;#39;t overwrite it with the toString() method
			// that props inherited from Object.prototype
			if((tobj[x] === undefined || tobj[x] != props[x]) &amp;amp;&amp;amp; props[x] !== undefined &amp;amp;&amp;amp; obj != props[x]){
				if(dojo.isObject(obj[x]) &amp;amp;&amp;amp; dojo.isObject(props[x])){
					if(dojo.isArray(props[x])){
						obj[x] = props[x];
					}else{
						obj[x] = jqMix(obj[x], props[x]);
					}
				}else{
					obj[x] = props[x];
				}
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3hw5-q855-g6cw</guid>
    </item>
    <item>
      <title>gsd-2020-5259</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-5259</link>
      <description>gsd-2020-5259</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-5259</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-5259</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-5259</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: dojo, Ubuntu:18.04:LTS: dojo, Ubuntu:Pro:20.04:LTS: dojo&lt;/p&gt;
&lt;p&gt;In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: dojo, Ubuntu:18.04:LTS: dojo, Ubuntu:Pro:20.04:LTS: dojo&lt;/p&gt;
&lt;p&gt;In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-5259</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0809 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</guid>
    </item>
  </channel>
</rss>
