Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32032 risultati

VulnerabilitàAlta
CVE-2026-3514 - Authentication Bypass in prefecthq/prefect

CVE ID :CVE-2026-3514 Published : June 2, 2026, 9:16 a.m. | 1 hour, 16 minutes ago Description :In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware exempts any URL path ending with 'health' or 'ready' from authentication checks. This allows an attacker to create resources with names ending in 'health' or 'ready' and access them without authentication. Affected endpoints include those for variables, flows, work pools, work queues, and deployments. This vulnerability can lead to unauthorized access to sensitive information, such as API keys and database credentials, stored in Prefect Variables. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
News
Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089

Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089 A critical Windows Netlogon vulnerability, tracked as CVE-2026-41089, has emerged as a significant security concern after authorities warned that threat actors are actively attempting to exploit the f ... Read more Published Date: Jun 02, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom02 giu 2026
VulnerabilitàAlta
CVE-2026-8293 - Really Simple Security < 9.5.10.1 - Authentication Bypass via Two-Factor OTP Skip

CVE ID :CVE-2026-8293 Published : June 2, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
News
Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication

Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication A critical authentication flaw in StrongDM’s desktop application has been identified that allows attackers to hijack user sessions by reusing locally stored authentication material, potentially exposi ... Read more Published Date: Jun 02, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4387

CVEfeed Newsroom02 giu 2026
News
Critical WP Maps Pro Vulnerability Allow Attackers to Create Administrator Account

Critical WP Maps Pro Vulnerability Allow Attackers to Create Administrator Account A critical security vulnerability in the popular WP Maps Pro WordPress plugin could allow attackers to gain full control of affected websites by creating unauthorized administrator accounts. The flaw, ... Read more Published Date: Jun 02, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-8732

CVEfeed Newsroom02 giu 2026
VulnerabilitàCritica
CVE-2026-8206 (CVSS 9.8)

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.

NVD (NIST)02 giu 2026
VulnerabilitàAlta
CVE-2026-3198 - Improper Access Control in mlflow/mlflow

CVE ID :CVE-2026-3198 Published : June 2, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries for `ListGatewaySecretInfos`, `ListGatewayEndpoints`, and `ListGatewayModelDefinitions`. This allows any authenticated user, regardless of their assigned permissions, to enumerate all gateway secrets, endpoints, and model definitions. This vulnerability exposes sensitive information, such as API keys, endpoint configurations, and proprietary model definitions, to unauthorized users. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-8206 - Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'

CVE ID :CVE-2026-8206 Published : June 2, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-10583 - nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import server-side request forgery

CVE ID :CVE-2026-10583 Published : June 2, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-10581 - DedeCMS download.php base64_decode server-side request forgery

CVE ID :CVE-2026-10581 Published : June 2, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-10548 - NousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authentication

CVE ID :CVE-2026-10548 Published : June 2, 2026, 2:16 a.m. | 4 hours, 16 minutes ago Description :A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-10559 - SourceCodester Pizzafy Ecommerce System index.php file inclusion

CVE ID :CVE-2026-10559 Published : June 2, 2026, 2:16 a.m. | 4 hours, 16 minutes ago Description :A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026

Pagina 1034 di 2670

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.