<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/github/10</id>
  <title>Most recent entries from github</title>
  <updated>2026-10-02T23:02:49.374938+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xxrc-g5c2-523g</id>
    <title>GHSA-xxrc-g5c2-523g</title>
    <updated>2026-09-02T00:31:27+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xxrc-g5c2-523g"/>
    <published>2026-08-18T15:31:45+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xx5w-j8g7-4v5f</id>
    <title>GHSA-xx5w-j8g7-4v5f</title>
    <updated>2023-12-13T18:30:59+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An argument injection vulnerability has been identified in the 
administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an 
unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain
 access as an arbitrary (administrative) user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xx5w-j8g7-4v5f"/>
    <published>2023-12-05T09:33:27+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xw3v-hx8p-r8v7</id>
    <title>GHSA-xw3v-hx8p-r8v7</title>
    <updated>2026-08-04T18:31:29+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability allowing remote unauthenticated code execution on the agent host.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xw3v-hx8p-r8v7"/>
    <published>2026-08-04T18:31:29+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xvh6-w8q3-q5g8</id>
    <title>GHSA-xvh6-w8q3-q5g8</title>
    <updated>2026-08-18T15:31:49+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xvh6-w8q3-q5g8"/>
    <published>2026-08-18T15:31:49+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xvg3-q6r5-8fhf</id>
    <title>GHSA-xvg3-q6r5-8fhf</title>
    <updated>2023-01-05T15:30:28+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xvg3-q6r5-8fhf"/>
    <published>2023-01-03T06:30:21+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xv32-fpqh-v67r</id>
    <title>GHSA-xv32-fpqh-v67r</title>
    <updated>2025-07-09T21:31:06+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xv32-fpqh-v67r"/>
    <published>2025-06-26T21:31:03+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xrc8-933j-f74c</id>
    <title>GHSA-xrc8-933j-f74c</title>
    <updated>2026-04-03T00:31:09+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xrc8-933j-f74c"/>
    <published>2026-04-03T00:31:09+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xr5v-45r7-33pq</id>
    <title>GHSA-xr5v-45r7-33pq</title>
    <updated>2024-04-04T01:34:12+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xr5v-45r7-33pq"/>
    <published>2022-05-24T16:52:41+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xqpc-xqhc-3crx</id>
    <title>GHSA-xqpc-xqhc-3crx</title>
    <updated>2026-06-19T15:33:15+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xqpc-xqhc-3crx"/>
    <published>2026-06-19T15:33:15+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xq74-c7jx-8w5j</id>
    <title>Withdrawn: GHSA-xq74-c7jx-8w5j — Duplicate Advisory: vm2 NodeVM can replace the host process TLS trust store</title>
    <updated>2026-10-01T15:27:12+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> npm: vm2</p>
<p>## Duplicate Advisory</p>
<p>This advisory has been withdrawn because it is a duplicate of GHSA-98xx-8mx4-x7cm. This link is maintained to preserve external references.</p>
<p>## Original Description
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xq74-c7jx-8w5j"/>
    <published>2026-09-17T15:32:15+00:00</published>
  </entry>
</feed>
