News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
33667 risultati
CVE ID :CVE-2026-55814 Published : Aug. 10, 2026, 10:21 a.m. | 8 minutes ago Description :Missing Authentication in Apache Ranger Download APIs on versions Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65942 Published : Aug. 10, 2026, 10:21 a.m. | 9 minutes ago Description :TLS hostname verification issue in Apache Ranger Client Code in versions Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65945 Published : Aug. 10, 2026, 10:20 a.m. | 9 minutes ago Description :Logs contain replayable JWT tokens in Apache Ranger versions Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-65948 Published : Aug. 10, 2026, 10:20 a.m. | 10 minutes ago Description :UnixAuth lacks brute-force protection in Apache Ranger versions Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66915 Published : Aug. 10, 2026, 10:17 a.m. | 12 minutes ago Description :Joomla Extension - fabrikar.com - Remote code execution in Fabrik Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-44630 Published : Aug. 10, 2026, 10:17 a.m. | 12 minutes ago Description :Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker can cause IoTDB to allocate an excessive amount of memory and crash with an OutOfMemoryError. This issue affects Apache IoTDB: before 1.3.8, from 2.0.0 before 2.0.9. Users are recommended to upgrade to version 2.0.10, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19404 Published : Aug. 10, 2026, 10:17 a.m. | 12 minutes ago Description :A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66642 Published : Aug. 10, 2026, 10:07 a.m. | 23 minutes ago Description :Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from n/a through 2.26.2. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities in GNU Emacs software Vulnerabilities in GNU Emacs software CVE ID CVE-2026-71391 Publication date 10 August 2026 Vendor GNU Product Emacs Vulnerable versions All through 30.2 Vulnerability type (CWE) Off-by-one Error (CWE ... Read more Published Date: Aug 10, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-71394 CVE-2026-71393 CVE-2026-71392 CVE-2026-71391
CVE ID :CVE-2026-66411 Published : Aug. 10, 2026, 9:17 a.m. | 1 hour, 13 minutes ago Description :DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66410 Published : Aug. 10, 2026, 9:17 a.m. | 1 hour, 13 minutes ago Description :Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66409 Published : Aug. 10, 2026, 9:17 a.m. | 1 hour, 13 minutes ago Description :DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 134 di 2806