Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32194 risultati

VulnerabilitàAlta
CVE-2026-24085 (CVSS 7.2)

Memory Corruption when processing display command line information due to improper initialization of a variable.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2026-24088 - Missing Authentication for Critical Function in Boot

CVE ID :CVE-2026-24088 Published : June 1, 2026, 11:16 p.m. | 1 hour, 16 minutes ago Description :Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-24091 - Improper Validation of Syntactic Correctness of Input in Display

CVE ID :CVE-2026-24091 Published : June 1, 2026, 11:16 p.m. | 1 hour, 16 minutes ago Description :Memory corruption while processing fastboot commands with improperly formatted input. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-24089 - Improper Validation of Syntactic Correctness of Input in Kernel

CVE ID :CVE-2026-24089 Published : June 1, 2026, 11:16 p.m. | 1 hour, 16 minutes ago Description :Memory corruption while processing fastboot commands with invalid input. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-24090 - Missing Authentication for Critical Function in HLOS

CVE ID :CVE-2026-24090 Published : June 1, 2026, 11:16 p.m. | 1 hour, 16 minutes ago Description :Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2025-59606 (CVSS 7.8)

Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2025-59605 (CVSS 7.8)

Memory Corruption when processing device identifier strings that exceed the expected maximum length.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2025-59604 (CVSS 7.8)

Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2019-25718 (CVSS 8.4)

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2026-25879 - Langroid has Prompt to SQL Injection, Leading to RCE

CVE ID :CVE-2026-25879 Published : June 1, 2026, 11:16 p.m. | 3 hours, 16 minutes ago Description :Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e.g., PostgreSQL pg_execute_server_program, MySQL FILE, MSSQL xp_cmdshell), an attacker who can shape the agent's input — including indirectly via data returned to the LLM — can coerce execution of dialect-specific primitives such as `COPY ... FROM PROGRAM`, achieving RCE on the database host. Fixed in v0.63.0 by defaulting SQLChatAgent to a SELECT-only sqlglot-parsed statement allowlist with a dialect-aware dangerous-pattern blocklist; allow_dangerous_operations=True restores the previous unrestricted behavior for trusted deployments. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-28511 - elabftw has entry title leakage through autocompletion search

CVE ID :CVE-2026-28511 Published : June 1, 2026, 11:16 p.m. | 7 hours, 16 minutes ago Description :eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user performing a numeric reference/search can return results that include resources the requesting user is not authorized to view. The exposed information is limited (only the title). Attempts to access the underlying protected resource content remain blocked by authorization checks. Version 5.4.2 fixes the issue. # Affected Scope Cross-scope visibility of titles. No confirmed bypass of content-level access controls # Preconditions An authenticated user account No special privileges required beyond standard access # Impact This may enable unauthorized disclosure of sensitive information if confidential data is included in resource titles. Examples could include project names, patient identifiers, or other regulated information embedded in titles. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-49491 (CVSS 8.2)

Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.

NVD (NIST)01 giu 2026

Pagina 1052 di 2683

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.