Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

31965 risultati

VulnerabilitàAlta
CVE-2026-35083 - Stack buffer overflow in method bac-deviceobject

CVE ID :CVE-2026-35083 Published : June 3, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-35081 - Arbitrary process termination vulnerability in method ugw-logstop

CVE ID :CVE-2026-35081 Published : June 3, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-35078 (CVSS 8.1)

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

NVD (NIST)03 giu 2026
VulnerabilitàAlta
CVE-2026-35077 (CVSS 8.1)

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

NVD (NIST)03 giu 2026
VulnerabilitàAlta
CVE-2026-35076 (CVSS 8.1)

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

NVD (NIST)03 giu 2026
VulnerabilitàCritica
CVE-2026-35075 (CVSS 9.8)

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

NVD (NIST)03 giu 2026
News
Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections

Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections A critical vulnerability in Apache ActiveMQ has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross ... Read more Published Date: Jun 03, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-49157 CVE-2026-42253

CVEfeed Newsroom03 giu 2026
News
Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege

Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege Ivanti has disclosed a high-severity vulnerability in its Ivanti Neurons for ITSM platform that could allow attackers with valid credentials to escalate privileges and gain full administrative access. ... Read more Published Date: Jun 03, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9614

CVEfeed Newsroom03 giu 2026
News
Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing

Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing A high-severity CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to interfere with outbound email processing in affected applications. The issue ... Read more Published Date: Jun 03, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom03 giu 2026
VulnerabilitàAlta
CVE-2026-41032 (CVSS 7.5)

It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

NVD (NIST)03 giu 2026
VulnerabilitàAlta
CVE-2025-15655 - WordPress School Management plugin <= 93.2.0 - SQL Injection vulnerability

CVE ID :CVE-2025-15655 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2025-15656 - WordPress School Management plugin <= 93.2.0 - Privilege Escalation vulnerability

CVE ID :CVE-2025-15656 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026

Pagina 1008 di 2664

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.