<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:03:54 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-06476</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06476</link>
      <description>bdu:2022-06476</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06476</guid>
    </item>
    <item>
      <title>certfr-2021-avi-490 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-490</link>
      <description>certfr-2021-avi-490</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-490</guid>
    </item>
    <item>
      <title>EUVD-2026-258290</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258290</link>
      <description>EUVD-2026-258290</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258290</guid>
    </item>
    <item>
      <title>fkie_cve-2021-23358</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-23358</link>
      <description>&lt;p&gt;The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-23358</guid>
    </item>
    <item>
      <title>GHSA-cf4h-3jhx-xvhq — Arbitrary Code Execution in underscore</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cf4h-3jhx-xvhq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: underscore&lt;/p&gt;
&lt;p&gt;The package `underscore` from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: underscore&lt;/p&gt;
&lt;p&gt;The package `underscore` from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cf4h-3jhx-xvhq</guid>
    </item>
    <item>
      <title>gsd-2021-23358</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-23358</link>
      <description>gsd-2021-23358</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-23358</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-23358 — Arbitrary Code Injection</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-23358</link>
      <description>msrc_CVE-2021-23358</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-23358</guid>
    </item>
    <item>
      <title>OESA-2021-1174 — nodejs-underscore security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1174</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs-underscore&lt;/p&gt;
&lt;p&gt;Underscore.js is a utility-belt library for JavaScript that provides support for the usual functional suspects (each, map, reduce, filter...) without extending any core JavaScript objects.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.(CVE-2021-23358)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs-underscore&lt;/p&gt;
&lt;p&gt;Underscore.js is a utility-belt library for JavaScript that provides support for the usual functional suspects (each, map, reduce, filter...) without extending any core JavaScript objects.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.(CVE-2021-23358)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1174</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0601-1 — Security update for nodejs-underscore</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0601-1</link>
      <description>&lt;p&gt;Security update for nodejs-underscore&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs-underscore&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0601-1</guid>
    </item>
    <item>
      <title>OXAS-ADV-2025-0001 — OX App Suite Security Advisory OXAS-ADV-2025-0001</title>
      <link>https://cve.radiocsirt.org/vuln/oxas-adv-2025-0001</link>
      <description>OXAS-ADV-2025-0001</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oxas-adv-2025-0001</guid>
    </item>
    <item>
      <title>RHSA-2021:1448 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.0.10 security and bug fix updates</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1448</link>
      <description>&lt;p&gt;nodejs-underscore: Arbitrary code execution via the template function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-underscore: Arbitrary code execution via the template function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1448</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-23358</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23358</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: underscore, Ubuntu:16.04:LTS: underscore, Ubuntu:18.04:LTS: underscore, Ubuntu:20.04:LTS: underscore&lt;/p&gt;
&lt;p&gt;The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: underscore, Ubuntu:16.04:LTS: underscore, Ubuntu:18.04:LTS: underscore, Ubuntu:20.04:LTS: underscore&lt;/p&gt;
&lt;p&gt;The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23358</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1354 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354</guid>
    </item>
  </channel>
</rss>
