Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

31977 risultati

News
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerabil ... Read more Published Date: Jun 03, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-0257 CVE-2026-39987 CVE-2025-53020 CVE-2024-21182 CVE-2016-6581 CVE-2016-8740 CVE-2016-1546

CVEfeed Newsroom03 giu 2026
VulnerabilitàAlta
CVE-2026-5078 - morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

CVE ID :CVE-2026-5078 Published : June 3, 2026, 8:16 a.m. | 4 hours, 16 minutes ago Description :Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header containing CR or LF bytes to inject forged log lines, breaking the one-request-per-line structure of access logs and enabling log forgery against downstream log consumers. The built-in combined, common, default, and short formats are affected, as well as any custom format that references :remote-user. Affected versions: morgan 1.2.0 through 1.10.1. Patches: upgrade to morgan 1.11.0, which neutralizes control characters in the :remote-user token output. Workarounds: use a custom format string that does not include :remote-user. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
News
Microsoft 365 Android Apps Account Takeover Vulnerability Impacted Billions of Android Users

Microsoft 365 Android Apps Account Takeover Vulnerability Impacted Billions of Android Users A single forgotten development flag left active in production code silently handed Microsoft account tokens to any app on an Android device, exposing billions of users across six major Microsoft 365 a ... Read more Published Date: Jun 03, 2026 (2 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-41102 CVE-2026-41101 CVE-2026-41100

CVEfeed Newsroom03 giu 2026
News
VS meldt misbruik van vier jaar oud beveiligingslek in Linux-kernel

VS meldt misbruik van vier jaar oud beveiligingslek in Linux-kernel Aanvallers maken actief misbruik van een vier jaar oude kwetsbaarheid in de Linux-kernel of hebben dit gedaan, zo waarschuwt het Amerikaanse cyberagentschap CISA. Het gaat om CVE-2022-0492, waardoor e ... Read more Published Date: Jun 03, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2022-0492

CVEfeed Newsroom03 giu 2026
News
Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers

Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers A newly disclosed flaw in the Windows search URI handler can silently leak NTLMv2 hashes to attacker-controlled servers with nothing more than a single link click. This behavior is the same bug class ... Read more Published Date: Jun 03, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33829

CVEfeed Newsroom03 giu 2026
News
HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora A newly disclosed remote denial-of-service exploit dubbed “HTTP/2 Bomb” targets the default HTTP/2 configurations of the world’s most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, E ... Read more Published Date: Jun 03, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom03 giu 2026
News
Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks

Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks Google has released its June 2026 Android security update, addressing 124 vulnerabilities, including one actively exploited zero-day. The zero-day — CVE-2025-48595 — is an integer overflow vulnerabili ... Read more Published Date: Jun 03, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom03 giu 2026
VulnerabilitàAlta
CVE-2026-50052 - Varnish Cache HTTP/2 Request Smuggling

CVE ID :CVE-2026-50052 Published : June 3, 2026, 6:16 a.m. | 6 hours, 16 minutes ago Description :In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter to contain +http2. HTTP/2 support is disabled by default. Severity: 2.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-50031 - FreeIPMI ipmi-oem Buffer Overflow

CVE ID :CVE-2026-50031 Published : June 3, 2026, 4:17 a.m. | 6 hours, 15 minutes ago Description :ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Two subcommands "ipmi-oem dell get-active-directory-config" and "ipmi-oem fujitsu get-sel-entry-long-text" were found to have exploitable buffer overflows on response messages. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-10704 (CVSS 7.3)

A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

NVD (NIST)03 giu 2026
VulnerabilitàAlta
CVE-2026-10704 - SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection

CVE ID :CVE-2026-10704 Published : June 3, 2026, 2:16 a.m. | 8 hours, 16 minutes ago Description :A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-10705 - dask HLL hyperloglog.py nunique_approx resource consumption

CVE ID :CVE-2026-10705 Published : June 3, 2026, 2:16 a.m. | 8 hours, 16 minutes ago Description :A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026

Pagina 1011 di 2665

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.