News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
33774 risultati
CVE ID :CVE-2026-42250 Published : May 28, 2026, 2:16 p.m. | 15 minutes ago Description :bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 version 1.0.9 Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-37266 Published : May 28, 2026, 2:16 p.m. | 16 minutes ago Description :An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-37579 Published : May 28, 2026, 2:16 p.m. | 16 minutes ago Description :An issue in SMSGate sms-core Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerability in Kidsview application Vulnerability in Kidsview application CVE ID CVE-2026-8990 Publication date 28 May 2026 Vendor View Concept Product Kidsview Vulnerable versions From 4.0.1 to 4.4.3 Vulnerability type (CWE) Authentica ... Read more Published Date: May 28, 2026 (4 days ago) Vulnerabilities has been mentioned in this article.
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better underst ... Read more Published Date: May 28, 2026 (3 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091 CVE-2026-45585 CVE-2026-42945 CVE-2026-31635 CVE-2026-33825
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, an ... Read more Published Date: May 28, 2026 (3 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45585 CVE-2026-8398 CVE-2026-42945 CVE-2026-31635
Gehackte FortiClient-servers verspreiden malware vermomd als Fortinet-patch Criminelen gebruiken gehackte Fortinet FortiClient-servers om binnen organisaties malware te verspreiden die vermomd is als een update van Fortinet. Dat meldt cybersecuritybedrijf Arctic Wolf. FortiCl ... Read more Published Date: May 28, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616
CVE ID :CVE-2026-9658 Published : May 28, 2026, 1:16 p.m. | 1 hour, 15 minutes ago Description :Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking header injections in the request paths unless they were double-encoded, for example, GET /path\r\nHTTP/1.1\r\nHost: secret.example.com Note that it is unclear whether request paths with CRLF followed by additional headers would be blocked by reverse proxies, or how they would be processed by Plack-based servers. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-9818 Published : May 28, 2026, 1:16 p.m. | 1 hour, 15 minutes ago Description :Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40914 Published : May 28, 2026, 1:16 p.m. | 1 hour, 15 minutes ago Description :A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. A user could successfully send a message to an address or consume a message from a queue with a routing-type not supported by the corresponding address when that operation should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address. Even though the user was already granted permission to send and/or consume messages, they should not be able to augment the routing-type of the address without the createAddress permission. This issue affects Apache Artemis: from 2.50.0 through 2.53.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0. Users are recommended to upgrade to version 2.54.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA adds Three Vulnerabilities to KEV Catalog May 28, 2026OverviewCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities catalog:CVE-2026-8398 (Daemon Tools Lite Embedded Malicious Code)CVE-2026-45321 (TanStack Unspecifie ... Read more Published Date: May 28, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-48027 CVE-2026-45659 CVE-2026-48172 CVE-2026-8398 CVE-2026-45321
Vulnerability in bzip2 software Vulnerability in bzip2 software CVE ID CVE-2026-42250 Publication date 28 May 2026 Vendor bzip2 Product bzip2 Vulnerable versions All before 1.0.9 Vulnerability type (CWE) Out-of-bounds Write (CWE-787 ... Read more Published Date: May 28, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article.
Pagina 1248 di 2815