Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32008 risultati

VulnerabilitàAlta
CVE-2026-45681 - OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size

CVE ID :CVE-2026-45681 Published : June 2, 2026, 4:16 p.m. | 16 minutes ago Description :OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer but preserves the original payload size, which can be up to 8KB. If a CPU mismatch occurs, OBI can read beyond the fallback buffer and leak adjacent memory into telemetry. This issue has been patched in version 0.9.0. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-45553 - NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()

CVE ID :CVE-2026-45553 Published : June 2, 2026, 4:16 p.m. | 16 minutes ago Description :NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI application passes attacker-controlled content to ui.restructured_text(), an attacker can use standard Docutils directives (include, csv-table with :file:, raw with :file:) to read local files readable by the NiceGUI server process. Applications that only pass trusted static strings to ui.restructured_text() are not affected. This issue has been patched in version 3.12.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-45554 - NiceGUI: Unauthenticated log-flood DoS via trailing slash on ESM and per-component resource routes

CVE ID :CVE-2026-45554 Published : June 2, 2026, 4:16 p.m. | 16 minutes ago Description :NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled RuntimeError inside Starlette's FileResponse, which Uvicorn writes to the server log as a full traceback. Because the routes are reachable without authentication, a remote attacker can amplify log volume and consume disk and log-pipeline capacity on any publicly reachable NiceGUI server. This issue has been patched in version 3.12.0. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-44367 - Klaw: user lockout due to case sensitivity inconsistency

CVE ID :CVE-2026-44367 Published : June 2, 2026, 4:16 p.m. | 16 minutes ago Description :Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling of username case sensitivity, leading to a targeted Denial of Service (DoS) and complete account lockout. This issue has been patched in version 2.10.4. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-45080 - Klaw: Improper Access Control Allows Disclosure of Password Hash

CVE ID :CVE-2026-45080 Published : June 2, 2026, 4:16 p.m. | 16 minutes ago Description :Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of password hash. This issue has been patched in version 2.10.4. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-42654 - WordPress Wallet System for WooCommerce plugin <= 2.7.5 - Broken Authentication vulnerability

CVE ID :CVE-2026-42654 Published : June 2, 2026, 4:16 p.m. | 16 minutes ago Description :Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-40619 - Genetec Security Center Local Privilege Escalation to Admin Credentials

CVE ID :CVE-2026-40619 Published : June 2, 2026, 4:16 p.m. | 16 minutes ago Description :A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation. This vulnerability is associated with specific installation package builds rather than the product version identifier alone. Certain versions (including 5.10.4.0, 5.11.3.0, 5.12.2.0 and 5.13.3.0) were released with both vulnerable and remediated installation packages under the same version number. Consequently, version-based comparison alone is insufficient to determine exposure. Only installations performed using vulnerable builds are affected. Remediated builds can be distinguished using verified installation package hashes. For the complete list of fixed build hashes, refer to the security advisory section. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-40780 - WordPress BookIt plugin < 2.5.4.1 - Broken Authentication vulnerability

CVE ID :CVE-2026-40780 Published : June 2, 2026, 4:16 p.m. | 16 minutes ago Description :Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a before 2.5.4.1. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
News
CISA Warns of Two-Year-Old Oracle WebLogic Server Vulnerability Exploited in Attacks

CISA Warns of Two-Year-Old Oracle WebLogic Server Vulnerability Exploited in Attacks CISA has issued a fresh warning highlighting active exploitation of a critical Oracle WebLogic Server vulnerability, tracked as CVE-2024-21182, adding it to its Known Exploited Vulnerabilities (KEV) c ... Read more Published Date: Jun 02, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-21182

CVEfeed Newsroom02 giu 2026
News
Critical KMW CCTV Vulnerability Let Attackers Gain Unauthorized Access to Camera Feeds

Critical KMW CCTV Vulnerability Let Attackers Gain Unauthorized Access to Camera Feeds A critical security flaw in KMW CCTV security cameras could allow attackers to gain full, unauthorized access to live camera feeds and device settings. The vulnerability, tracked as CVE-2026-5386, has ... Read more Published Date: Jun 02, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5386

CVEfeed Newsroom02 giu 2026
VulnerabilitàAlta
CVE-2026-9844 - Vulnerability in navify® Digital Pathology

CVE ID :CVE-2026-9844 Published : June 2, 2026, 2:17 p.m. | 15 minutes ago Description :Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-7313 - CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity

CVE ID :CVE-2026-7313 Published : June 2, 2026, 2:17 p.m. | 15 minutes ago Description :CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration and valid back-end authorization. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026

Pagina 1025 di 2668

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.