Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32953 risultati

VulnerabilitàAlta
CVE-2026-10221 (CVSS 7.3)

A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2026-10220 (CVSS 7.3)

A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2026-10219 (CVSS 7.3)

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2026-20453 - Geniezone Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20453 Published : June 1, 2026, 4:16 a.m. | 2 hours, 16 minutes ago Description :In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10221 - NousResearch hermes-agent run_agent.py _compress_context injection

CVE ID :CVE-2026-10221 Published : June 1, 2026, 4:16 a.m. | 2 hours, 16 minutes ago Description :A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10219 - nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection

CVE ID :CVE-2026-10219 Published : June 1, 2026, 4:16 a.m. | 2 hours, 16 minutes ago Description :A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10220 - NousResearch hermes-agent skills_tool.py skill_view injection

CVE ID :CVE-2026-10220 Published : June 1, 2026, 4:16 a.m. | 2 hours, 16 minutes ago Description :A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-20452 - "Qualcomm WCN wlan AP Driver Heap Buffer Overflow"

CVE ID :CVE-2026-20452 Published : June 1, 2026, 4:16 a.m. | 2 hours, 16 minutes ago Description :In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10217 - nextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges management

CVE ID :CVE-2026-10217 Published : June 1, 2026, 4:16 a.m. | 2 hours, 16 minutes ago Description :A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin Gateway. This manipulation causes improper privilege management. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project tagged the reported issue as bug. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10218 - nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization

CVE ID :CVE-2026-10218 Published : June 1, 2026, 4:16 a.m. | 2 hours, 16 minutes ago Description :A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The project tagged the reported issue as bug. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10216 - unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication

CVE ID :CVE-2026-10216 Published : June 1, 2026, 4:16 a.m. | 2 hours, 16 minutes ago Description :A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
News
Windows Netlogon 0-Click RCE Vulnerability Now Actively Exploited In The Wild

Windows Netlogon 0-Click RCE Vulnerability Now Actively Exploited In The Wild The critical Windows Netlogon remote code execution (RCE) vulnerability tracked as CVE-2026-41089 is now under active exploitation in the wild, significantly raising the risk profile for unpatched Win ... Read more Published Date: Jun 01, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-41089

CVEfeed Newsroom01 giu 2026

Pagina 1135 di 2747

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.