News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
34881 risultati
CVE ID :CVE-2026-40914 Published : May 28, 2026, 1:16 p.m. | 1 hour, 15 minutes ago Description :A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. A user could successfully send a message to an address or consume a message from a queue with a routing-type not supported by the corresponding address when that operation should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address. Even though the user was already granted permission to send and/or consume messages, they should not be able to augment the routing-type of the address without the createAddress permission. This issue affects Apache Artemis: from 2.50.0 through 2.53.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0. Users are recommended to upgrade to version 2.54.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA adds Three Vulnerabilities to KEV Catalog May 28, 2026OverviewCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities catalog:CVE-2026-8398 (Daemon Tools Lite Embedded Malicious Code)CVE-2026-45321 (TanStack Unspecifie ... Read more Published Date: May 28, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-48027 CVE-2026-45659 CVE-2026-48172 CVE-2026-8398 CVE-2026-45321
Vulnerability in bzip2 software Vulnerability in bzip2 software CVE ID CVE-2026-42250 Publication date 28 May 2026 Vendor bzip2 Product bzip2 Vulnerable versions All before 1.0.9 Vulnerability type (CWE) Out-of-bounds Write (CWE-787 ... Read more Published Date: May 28, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article.
Vulnerability in D-Link DWR-X1820 router Vulnerability in D-Link DWR-X1820 router CVE ID CVE-2026-4377 Publication date 28 May 2026 Vendor D-Link Corporation Product DWR-X1820 Vulnerable versions From 1.00B14CP to 1.00B16CP Vulnerability typ ... Read more Published Date: May 28, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article.
Gitea Container Vulnerability Exposes Private Container Images to Attackers A critical security vulnerability in Gitea’s built-in container registry exposes private container images to unauthenticated attackers, raising significant concerns for organizations that rely on self ... Read more Published Date: May 28, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-9813 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. Due to insufficient validation of the URL scheme and resolved destination address, affected versions may allow requests to loopback, link-local, private, reserved, or other restricted network resources, potentially enabling interaction with internal services or cloud metadata endpoints from the server's network context. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-46241 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on registration failure Make sure to disable and free the interrupts in case controller registration fails to avoid a potential use-after-free and resource leak. This issue was flagged by Sashiko when reviewing a controller deregistration fix. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-46240 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix use-after-free in iris_release_internal_buffers() The recent change in commit 1dabf00ee206 ("media: iris: gen1: Destroy internal buffers after FW releases") introduced a regression where session_release_buf() may free the buffer. The caller, iris_release_internal_buffers(), continued to access `buffer` after the call, leading to a potential use-after-free. Fix this by setting BUF_ATTR_PENDING_RELEASE before calling session_release_buf(), and reverting the flag if the call fails. This ensures no dereference occurs after potential freeing. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4377 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the default password if they have the device IMEI number. This issue was fixed in version 1.00B16CP. Severity: 6.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-46237 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Avoid overflow on msg bound check As pointed out by SDL, the previous condition may be vulnerable to overflow. (cherry picked from commit db00257ac9e4a51eb2515aaea161a019f7125e10) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-46239 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov5647: Fix runtime PM refcount leak in s_ctrl Three control cases (AUTOGAIN, EXPOSURE_AUTO, ANALOGUE_GAIN) directly return without calling pm_runtime_put(), causing runtime PM reference count leaks. Change these cases from 'return' to 'ret = ... break' pattern to ensure pm_runtime_put() is always called before function exit. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-47074 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/ex_aws/sns.ex, lib/ex_aws/sns/public_key_cache.ex and program routines 'Elixir.ExAws.SNS':verify_message/1, 'Elixir.ExAws.SNS.PublicKeyCache':get/1. 'Elixir.ExAws.SNS':verify_message/1 fetches the signing certificate from the SigningCertURL field of the incoming SNS message without validating that the URL uses HTTPS or that the host matches an AWS-owned SNS certificate domain. An unauthenticated attacker who can POST to an endpoint that calls verify_message/1 can supply an attacker-controlled SigningCertURL, sign a forged SNS message with their own key, and cause the function to return :ok, completely bypassing SNS signature verification. This issue affects ex_aws_sns: from 2.0.1 before 2.3.5. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1341 di 2907