Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35137 risultati

News
FortiClient Code Execution Vulnerability Exploited to Deploy EKZ Malware

FortiClient Code Execution Vulnerability Exploited to Deploy EKZ Malware A newly observed exploitation campaign targeting FortiClient Endpoint Management Server (EMS) has weaponized trusted administrative infrastructure to silently deploy a previously unreported credential ... Read more Published Date: May 28, 2026 (2 days, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616

CVEfeed Newsroom28 mag 2026
VulnerabilitàAlta
CVE-2026-9789 - NitroSense V3: Security Vulnerability Information

CVE ID :CVE-2026-9789 Published : May 28, 2026, 3:16 a.m. | 1 hour, 15 minutes ago Description :A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the service does not check the caller's privileges before running file deletion commands, a low-privileged local user can exploit this to delete arbitrary files with system authority. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
News
CVE-2026-48172 — LiteSpeed User-End cPanel Plugin Privilege Escalation

CVE-2026-48172 — LiteSpeed User-End cPanel Plugin Privilege Escalation May 28, 2026OverviewCISA has added CVE-2026-48172 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The flaw is a maximum-severity privilege escalation vulner ... Read more Published Date: May 28, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-48172

CVEfeed Newsroom28 mag 2026
VulnerabilitàAlta
CVE-2026-4888 - Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending

CVE ID :CVE-2026-4888 Published : May 28, 2026, 12:16 a.m. | 4 hours, 15 minutes ago Description :The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send test emails to arbitrary addresses from the server. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-8915 - Samsung Escargot Out-of-Bounds Write Buffer Overflow

CVE ID :CVE-2026-8915 Published : May 28, 2026, 12:16 a.m. | 4 hours, 15 minutes ago Description :Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-9208 - Tanium addressed an unauthorized code execution vulnerability in Connect.

CVE ID :CVE-2026-9208 Published : May 27, 2026, 10:16 p.m. | 6 hours, 15 minutes ago Description :Tanium addressed an unauthorized code execution vulnerability in Connect. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-44720 - OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover

CVE ID :CVE-2026-44720 Published : May 27, 2026, 10:16 p.m. | 6 hours, 15 minutes ago Description :OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. This vulnerability is fixed in 2.0.4. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-45083 - Goobi viewer: Unauthenticated Solr Streaming Expression Proxy

CVE ID :CVE-2026-45083 Published : May 27, 2026, 10:16 p.m. | 6 hours, 15 minutes ago Description :The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unauthenticated network clients and forwarded it to the backend Solr server without restriction. An attacker could read the complete Solr index and, in default Solr deployments, also modify or delete indexed records. This vulnerability is fixed in 26.04.1. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-45152 - uniget: Command Injection in tool.Check Leading to Arbitrary Code Execution

CVE ID :CVE-2026-45152 Published : May 27, 2026, 10:16 p.m. | 6 hours, 15 minutes ago Description :uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files using /bin/bash -c. Because the check field is loaded directly from untrusted JSON metadata without validation or sanitization, an attacker can craft malicious metadata that executes arbitrary shell commands on the victim’s system when common uniget operations such as describe, install, update, or inspect are performed. This vulnerability can lead to arbitrary code execution with the privileges of the user running uniget. This vulnerability is fixed in 0.27.1. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-44247 - Volcano: Webhook server vulnerable to OOM due to unbounded HTTP request body size

CVE ID :CVE-2026-44247 Published : May 27, 2026, 10:16 p.m. | 6 hours, 15 minutes ago Description :Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluster pod that can reach the webhook endpoint may send an arbitrarily large request body, potentially causing the webhook server to be killed by OOM. All Volcano deployments with the webhook server exposed to in-cluster traffic are affected. This vulnerability is fixed in v1.14.2, v1.13.3, and v1.12.4. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-46538 - Microsoft UFO accepts cross-device TASK_END messages by session_id only, allowing peer task-result injection

CVE ID :CVE-2026-46538 Published : May 27, 2026, 11:16 p.m. | 5 hours, 15 minutes ago Description :Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id only and does not verify that a TASK_END message came from the device that originally received the task. When the constellation sends a task to a target device, it records a pending Future under a session key. The pending task record stores the expected device ID, but the completion path ignores that binding. If another authenticated peer device sends a forged TASK_END with the same session_id, the constellation accepts the response and completes the victim device's pending Future with attacker-controlled result data. This is an authenticated cross-device task-result injection issue. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-46416 - Microsoft UFO shared WebSocket handler state causes cross-client response hijacking

CVE ID :CVE-2026-46416 Published : May 27, 2026, 11:16 p.m. | 5 hours, 15 minutes ago Description :Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and reuses it for multiple authenticated WebSocket connections. The handler stores per-connection protocol objects in mutable instance fields. Each new WebSocket connection overwrites those fields. Later, message handlers send responses through the shared fields instead of through protocol objects bound to the originating connection. As a result, the most recently connected authenticated client can receive protocol responses that belong to another authenticated client. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026

Pagina 1369 di 2929

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.