Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32453 risultati

VulnerabilitàAlta
CVE-2026-10261 - CodeAstro Online Job Portal application_status.php sql injection

CVE ID :CVE-2026-10261 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10260 - CodeAstro Online Job Portal delete-jobs.php sql injection

CVE ID :CVE-2026-10260 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10259 (CVSS 8.8)

A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2026-10259 - H3C Magic B0 aspForm SetMobileAPInfoById stack-based overflow

CVE ID :CVE-2026-10259 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-0826 - Poly Voice – Possible Remote Control of Certain Poly Devices

CVE ID :CVE-2026-0826 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2025-60495 - GPAC MP4Box Integer Overflow Denial of Service

CVE ID :CVE-2025-60495 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2025-60486 - GPAC MP4Box Heap Use-After-Free Denial of Service

CVE ID :CVE-2025-60486 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
News
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: pois ... Read more Published Date: Jun 01, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom01 giu 2026
VulnerabilitàAlta
CVE-2026-9308 - Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order

CVE ID :CVE-2026-9308 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-9309 - Arbitrary JavaScript execution in internal pages via Reader View JSON-LD injection

CVE ID :CVE-2026-9309 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-34193 - GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()

CVE ID :CVE-2026-34193 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10257 - itsourcecode Content Management System update_ss_img.php sql injection

CVE ID :CVE-2026-10257 Published : June 1, 2026, 1:16 p.m. | 1 hour, 16 minutes ago Description :A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026

Pagina 1085 di 2705

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.