Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32027 risultati

VulnerabilitàAlta
CVE-2026-10622 - CVE-2026-10622

CVE ID :CVE-2026-10622 Published : June 2, 2026, 2:16 p.m. | 16 minutes ago Description :Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-10611 - OTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authentication is enabled

CVE ID :CVE-2026-10611 Published : June 2, 2026, 2:16 p.m. | 16 minutes ago Description :An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authenticated through an authentication plugin, such as LDAP, may have their authenticated session established during the application beforeFilter phase before the normal login flow enforces the OTP challenge. As a result, an attacker with valid primary authentication credentials could bypass the required OTP step by authenticating through the plugin-backed login flow and then directly accessing another application URL instead of completing the OTP verification page. This allows access to the application as the affected user without providing a valid TOTP, HOTP, or email OTP code. The issue affects configurations where plugin-based authentication is enabled and OTP is expected to be mandatory. The fix ensures that OTP requirements are checked immediately after plugin authentication and before the user session is established, redirecting users to the appropriate OTP challenge when required. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2025-68886 - WordPress Cookiteer theme <= 1.4.8 - Local File Inclusion vulnerability

CVE ID :CVE-2025-68886 Published : June 2, 2026, 2:16 p.m. | 16 minutes ago Description :Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2025-69369 - WordPress Racquet theme <= 1.12.0 - Local File Inclusion vulnerability

CVE ID :CVE-2025-69369 Published : June 2, 2026, 2:16 p.m. | 16 minutes ago Description :Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2025-58897 - WordPress Fermentio theme <= 1.5.0 - Local File Inclusion vulnerability

CVE ID :CVE-2025-58897 Published : June 2, 2026, 2:16 p.m. | 16 minutes ago Description :Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. This issue affects Fermentio: from n/a through 1.5.0. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2025-58707 - WordPress Spin theme <= 1.8 - Local File Inclusion vulnerability

CVE ID :CVE-2025-58707 Published : June 2, 2026, 2:16 p.m. | 16 minutes ago Description :Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2019-25719 (CVSS 8.6)

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality.

NVD (NIST)02 giu 2026
News
Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix

Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix Acknowledgments:A special thank you to Tyler Bohlmann, Jon Semon, Lindsey O'Donnell-Welch, Aaron Deal, and Beth Robinson for their contributions and edits to this blog. And a big thank you to Casey Sm ... Read more Published Date: Jun 02, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33829

CVEfeed Newsroom02 giu 2026
News
CISA Flags Palo Alto Networks PAN-OS Vulnerability as Exploited in Attacks

CISA Flags Palo Alto Networks PAN-OS Vulnerability as Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Palo Alto Networks PAN-OS vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that the fla ... Read more Published Date: Jun 02, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-0257

CVEfeed Newsroom02 giu 2026
News
Microsoft MSRC Allegedly Dismissed Dependency Confusion Vulnerability, Claims Researcher

Microsoft MSRC Allegedly Dismissed Dependency Confusion Vulnerability, Claims Researcher A dependency confusion vulnerability affecting Microsoft’s Azure Portal after the Microsoft Security Response Center (MSRC) closed the case, claiming the confirmed remote code execution evidence did n ... Read more Published Date: Jun 02, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091 CVE-2026-45585 CVE-2026-33825

CVEfeed Newsroom02 giu 2026
VulnerabilitàAlta
CVE-2026-8993 - Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks

CVE ID :CVE-2026-8993 Published : June 2, 2026, 12:16 p.m. | 16 minutes ago Description :D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-42685 - WordPress WP Job Portal plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-42685 Published : June 2, 2026, 12:16 p.m. | 16 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026

Pagina 1029 di 2669

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.