Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32000 risultati

News
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per S ... Read more Published Date: Jun 02, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45585 CVE-2026-42945 CVE-2026-31635 CVE-2026-21509 CVE-2025-8088

CVEfeed Newsroom02 giu 2026
News
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, ba ... Read more Published Date: Jun 02, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45585 CVE-2026-42945 CVE-2026-31635 CVE-2026-21962 CVE-2024-21182

CVEfeed Newsroom02 giu 2026
News
Cyber Brief 26-06 - May 2026

Cyber Brief 26-06 - May 2026 Cyber Brief (May 2026)June 2, 2026 - Version: 1TLP:CLEARExecutive summaryWe analysed 325 open source reports for this Cyber Brief1.Relating to cyber policy and law enforcement, Europol supported inter ... Read more Published Date: Jun 02, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45585 CVE-2026-43284 CVE-2026-0300 CVE-2026-33825 CVE-2026-35616

CVEfeed Newsroom02 giu 2026
VulnerabilitàAlta
CVE-2026-49943 - CZ.NIC BIRD Internet Routing Daemon Stack-Based Buffer Overflow

CVE ID :CVE-2026-49943 Published : June 2, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses a fixed-size stack array of 2048 + 1 pm_pos entries, while parse_path() expands AS_PATH segments from a received BGP UPDATE without enforcing a corresponding capacity limit. When RFC 8654 BGP Extended Messages are enabled and a BIRD filter evaluates an AS path mask expression such as "bgp_path ~ [= ... =]", an established BGP peer can send a long AS_PATH containing more than 2048 expanded ASNs. This causes parse_path()/as_path_match() to write beyond the fixed stack buffer, resulting in a crash of the daemon. NOTE: reportedly, the Supplier's position is that a fix is not being prioritized because all network operators should already be rejecting routes with unusually long attributes. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-42074 - OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input

CVE ID :CVE-2026-42074 Published : June 2, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted principal per the project's own threat model) can set it to true in any tool_use response. Combined with the default allowUnsandboxedCommands: true setting, a prompt-injected model can escape the sandbox for any arbitrary command, achieving full host-level code execution. This issue has been patched in version 0.5.1. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-42073 - OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS

CVE ID :CVE-2026-42073 Published : June 2, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP server to handle OAuth callbacks. To prevent CSRF attacks, the server validates a state parameter against an internally stored value. However, due to a logic flaw in the order of conditionals, an attacker can completely bypass this check and force the server to shut down — without knowing the state value at all. This issue has been patched in version 0.5.1. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-40571 - NamelessMC: Reactions on private or blocking profile posts can be modified without proper authorization

CVE ID :CVE-2026-40571 Published : June 2, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This means that authenticated low-privileged users can add reactions to private or blocking profile posts. Version 2.2.5 contains a patch. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-40715 - Dell ThinOS Improper Access Control Privilege Escalation

CVE ID :CVE-2026-40715 Published : June 2, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-40713 - Dell ThinOS Improper Access Control Information Exposure

CVE ID :CVE-2026-40713 Published : June 2, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-33244 - React Router has stored XSS via unescaped Location header in prerendered redirect HTML

CVE ID :CVE-2026-33244 Published : June 2, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (``) or Data Mode (`createBrowserRouter/`). This is patched in version 7.13.2. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-40314 - NamelessMC: Reactions on private or blocking profile posts can be read and modified without proper authorization

CVE ID :CVE-2026-40314 Published : June 2, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/queries/reactions.php` allows unauthenticated GET requests for reaction details. This means that unauthenticated visitors can read reaction participants and timestamps for private profile posts and uthenticated low-privileged users can add reactions to private or blocking profile posts. Version 2.2.5 fixes the issue. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-35447 - NamelessMC: Private or blocking profile pages can be bypassed with direct POST requests, and reply handling allows cross-profile writes

CVE ID :CVE-2026-35447 Published : June 2, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the profile.post permission to write wall posts to private or blocking profiles. Additionally, the reply branch does not verify that the target wall post belongs to the current profile, enabling attackers to inject replies into arbitrary wall posts owned by other profiles via a restricted profile URL. This is patched in version 2.2.5. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026

Pagina 1021 di 2667

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.