Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32353 risultati

VulnerabilitàAlta
CVE-2026-0826 - Poly Voice – Possible Remote Control of Certain Poly Devices

CVE ID :CVE-2026-0826 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2025-60495 - GPAC MP4Box Integer Overflow Denial of Service

CVE ID :CVE-2025-60495 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2025-60486 - GPAC MP4Box Heap Use-After-Free Denial of Service

CVE ID :CVE-2025-60486 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
News
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: pois ... Read more Published Date: Jun 01, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom01 giu 2026
VulnerabilitàAlta
CVE-2026-9308 - Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order

CVE ID :CVE-2026-9308 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-9309 - Arbitrary JavaScript execution in internal pages via Reader View JSON-LD injection

CVE ID :CVE-2026-9309 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-34193 - GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()

CVE ID :CVE-2026-34193 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10532 - Logback deserialization whitelist bypass for Proxy objects

CVE ID :CVE-2026-10532 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects. Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions. This issue affects logback: through 1.5.33 inclusive. Severity: 2.9 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10257 - itsourcecode Content Management System update_ss_img.php sql injection

CVE ID :CVE-2026-10257 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10258 - itsourcecode Content Management System add_sub_topic.php sql injection

CVE ID :CVE-2026-10258 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument topic_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10253 (CVSS 7.3)

A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2026-10252 (CVSS 7.3)

A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

NVD (NIST)01 giu 2026

Pagina 1077 di 2697

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.