<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from github</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:43:14 +0000</lastBuildDate>
    <item>
      <title>GHSA-xxrc-g5c2-523g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xxrc-g5c2-523g</link>
      <description>&lt;p&gt;Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xxrc-g5c2-523g</guid>
      <pubDate>Tue, 18 Aug 2026 15:31:45 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-xx5w-j8g7-4v5f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xx5w-j8g7-4v5f</link>
      <description>&lt;p&gt;An argument injection vulnerability has been identified in the 
administrative web interface of the Atos Unify OpenScape products &amp;#34;Session Border Controller&amp;#34; (SBC) and &amp;#34;Branch&amp;#34;, before version V10 R3.4.0, and OpenScape &amp;#34;BCF&amp;#34; before versions V10R10.12.00 and V10R11.05.02. This allows an 
unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain
 access as an arbitrary (administrative) user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An argument injection vulnerability has been identified in the 
administrative web interface of the Atos Unify OpenScape products &amp;#34;Session Border Controller&amp;#34; (SBC) and &amp;#34;Branch&amp;#34;, before version V10 R3.4.0, and OpenScape &amp;#34;BCF&amp;#34; before versions V10R10.12.00 and V10R11.05.02. This allows an 
unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain
 access as an arbitrary (administrative) user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xx5w-j8g7-4v5f</guid>
      <pubDate>Tue, 05 Dec 2023 09:33:27 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-xw3v-hx8p-r8v7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xw3v-hx8p-r8v7</link>
      <description>&lt;p&gt;A vulnerability allowing remote unauthenticated code execution on the agent host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability allowing remote unauthenticated code execution on the agent host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xw3v-hx8p-r8v7</guid>
      <pubDate>Tue, 04 Aug 2026 18:31:29 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-xvh6-w8q3-q5g8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xvh6-w8q3-q5g8</link>
      <description>&lt;p&gt;A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xvh6-w8q3-q5g8</guid>
      <pubDate>Tue, 18 Aug 2026 15:31:49 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-xvg3-q6r5-8fhf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xvg3-q6r5-8fhf</link>
      <description>&lt;p&gt;Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xvg3-q6r5-8fhf</guid>
      <pubDate>Tue, 03 Jan 2023 06:30:21 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-xv32-fpqh-v67r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xv32-fpqh-v67r</link>
      <description>&lt;p&gt;An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xv32-fpqh-v67r</guid>
      <pubDate>Thu, 26 Jun 2025 21:31:03 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-xrc8-933j-f74c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xrc8-933j-f74c</link>
      <description>&lt;p&gt;Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xrc8-933j-f74c</guid>
      <pubDate>Fri, 03 Apr 2026 00:31:09 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-xr5v-45r7-33pq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xr5v-45r7-33pq</link>
      <description>&lt;p&gt;NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xr5v-45r7-33pq</guid>
      <pubDate>Tue, 24 May 2022 16:52:41 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-xqpc-xqhc-3crx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xqpc-xqhc-3crx</link>
      <description>&lt;p&gt;In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xqpc-xqhc-3crx</guid>
      <pubDate>Fri, 19 Jun 2026 15:33:15 +0000</pubDate>
    </item>
    <item>
      <title>Withdrawn: GHSA-xq74-c7jx-8w5j — Duplicate Advisory: vm2 NodeVM can replace the host process TLS trust store</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xq74-c7jx-8w5j</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because it is a duplicate of GHSA-98xx-8mx4-x7cm. This link is maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;## Original Description
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because it is a duplicate of GHSA-98xx-8mx4-x7cm. This link is maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;## Original Description
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xq74-c7jx-8w5j</guid>
      <pubDate>Thu, 17 Sep 2026 15:32:15 +0000</pubDate>
    </item>
  </channel>
</rss>
