News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
31965 risultati
CVE ID :CVE-2026-35083 Published : June 3, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-35081 Published : June 3, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections A critical vulnerability in Apache ActiveMQ has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross ... Read more Published Date: Jun 03, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-49157 CVE-2026-42253
Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege Ivanti has disclosed a high-severity vulnerability in its Ivanti Neurons for ITSM platform that could allow attackers with valid credentials to escalate privileges and gain full administrative access. ... Read more Published Date: Jun 03, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9614
Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing A high-severity CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to interfere with outbound email processing in affected applications. The issue ... Read more Published Date: Jun 03, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article.
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
CVE ID :CVE-2025-15655 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-15656 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1008 di 2664