Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33667 risultati

VulnerabilitàAlta
CVE-2026-55814 - Apache Ranger: Download APIs expose plugin data without authentication

CVE ID :CVE-2026-55814 Published : Aug. 10, 2026, 10:21 a.m. | 8 minutes ago Description :Missing Authentication in Apache Ranger Download APIs on versions Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-65942 - Apache Ranger: Clients accept TLS certificates issued for other hostnames

CVE ID :CVE-2026-65942 Published : Aug. 10, 2026, 10:21 a.m. | 9 minutes ago Description :TLS hostname verification issue in Apache Ranger Client Code in versions Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-65945 - Apache Ranger: Logs contain replayable JWT bearer tokens

CVE ID :CVE-2026-65945 Published : Aug. 10, 2026, 10:20 a.m. | 9 minutes ago Description :Logs contain replayable JWT tokens in Apache Ranger versions Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-65948 - Apache Ranger: UnixAuth lacks brute-force protection

CVE ID :CVE-2026-65948 Published : Aug. 10, 2026, 10:20 a.m. | 10 minutes ago Description :UnixAuth lacks brute-force protection in Apache Ranger versions Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-66915 - Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.7

CVE ID :CVE-2026-66915 Published : Aug. 10, 2026, 10:17 a.m. | 12 minutes ago Description :Joomla Extension - fabrikar.com - Remote code execution in Fabrik Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-44630 - Apache IoTDB: RPC service denial of service via unchecked Thrift string length

CVE ID :CVE-2026-44630 Published : Aug. 10, 2026, 10:17 a.m. | 12 minutes ago Description :Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker can cause IoTDB to allocate an excessive amount of memory and crash with an OutOfMemoryError. This issue affects Apache IoTDB: before 1.3.8, from 2.0.0 before 2.0.9. Users are recommended to upgrade to version 2.0.10, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-19404 - 389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abort cleanallruv replication maintenance

CVE ID :CVE-2026-19404 Published : Aug. 10, 2026, 10:17 a.m. | 12 minutes ago Description :A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-66642 - WordPress WP Umbrella plugin <= 2.26.2 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-66642 Published : Aug. 10, 2026, 10:07 a.m. | 23 minutes ago Description :Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from n/a through 2.26.2. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
News
Vulnerabilities in GNU Emacs software

Vulnerabilities in GNU Emacs software Vulnerabilities in GNU Emacs software CVE ID CVE-2026-71391 Publication date 10 August 2026 Vendor GNU Product Emacs Vulnerable versions All through 30.2 Vulnerability type (CWE) Off-by-one Error (CWE ... Read more Published Date: Aug 10, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-71394 CVE-2026-71393 CVE-2026-71392 CVE-2026-71391

CVEfeed Newsroom6g fa
VulnerabilitàAlta
CVE-2026-66411 - Ecovacs DEEBOT PRO Authentication Bypass Vulnerability

CVE ID :CVE-2026-66411 Published : Aug. 10, 2026, 9:17 a.m. | 1 hour, 13 minutes ago Description :DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-66410 - ECOVACS PRO App Improper Certificate Validation Vulnerability

CVE ID :CVE-2026-66410 Published : Aug. 10, 2026, 9:17 a.m. | 1 hour, 13 minutes ago Description :Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-66409 - ECOVACS DEEBOT Weak Wi-Fi Hotspot Password Vulnerability

CVE ID :CVE-2026-66409 Published : Aug. 10, 2026, 9:17 a.m. | 1 hour, 13 minutes ago Description :DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa

Pagina 134 di 2806

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.