Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35286 risultati

VulnerabilitàAlta
CVE-2026-8606 - Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint

CVE ID :CVE-2026-8606 Published : May 27, 2026, 12:16 a.m. | 2 hours, 15 minutes ago Description :A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal management service and measuring response timing, an attacker could infer the values of sensitive environment variables, including signing secrets and private keys. Exploitation required GitHub Packages to be enabled; on instances not running in private mode the vulnerability was exploitable without authentication, otherwise any authenticated user could exploit it. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21.1 and was fixed in versions 3.20.3, 3.19.7, 3.18.10, 3.17.16, and 3.16.19. This vulnerability was reported via the GitHub Bug Bounty program. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-9604 - JeecgBoot AiragModelController access control

CVE ID :CVE-2026-9604 Published : May 26, 2026, 11:16 p.m. | 3 hours, 15 minutes ago Description :A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 3.9.2 is able to resolve this issue. The affected component should be upgraded. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-8647 - Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available

CVE ID :CVE-2026-8647 Published : May 26, 2026, 11:16 p.m. | 3 hours, 15 minutes ago Description :Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::Random::Secure were available. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-8680 - Apache HTTP Server Remote Code Execution

CVE ID :CVE-2026-8680 Published : May 26, 2026, 11:16 p.m. | 3 hours, 15 minutes ago Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-46740 - Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections

CVE ID :CVE-2026-46740 Published : May 26, 2026, 11:16 p.m. | 3 hours, 15 minutes ago Description :Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd client to using a separate statsd client. It defaults to using a version of Net::Statsd::Tiny that fixes a similar issue (CVE-2026-46720). Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9584 (CVSS 7.3)

A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

NVD (NIST)26 mag 2026
VulnerabilitàAlta
CVE-2026-5260 (CVSS 8.2)

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

NVD (NIST)26 mag 2026
VulnerabilitàAlta
CVE-2026-9603 - SourceCodester eDoc Doctor Appointment System delete-session.php authorization

CVE ID :CVE-2026-9603 Published : May 26, 2026, 10:16 p.m. | 4 hours, 15 minutes ago Description :A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9584 - code-projects Project Management System Login chk.php sql injection

CVE ID :CVE-2026-9584 Published : May 26, 2026, 10:16 p.m. | 4 hours, 15 minutes ago Description :A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-5260 - Gnutls: gnutls: information disclosure via heap overread in rsa key exchange

CVE ID :CVE-2026-5260 Published : May 26, 2026, 10:16 p.m. | 4 hours, 15 minutes ago Description :A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-48710 - Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

CVE ID :CVE-2026-48710 Published : May 26, 2026, 10:16 p.m. | 4 hours, 15 minutes ago Description :Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-45574 - epa4all-client: TLS Certificate Validation Disabled in Production

CVE ID :CVE-2026-45574 Published : May 26, 2026, 10:16 p.m. | 2 hours, 15 minutes ago Description :epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential exchanges. This vulnerability is fixed in 1.2.2. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026

Pagina 1405 di 2941

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.