Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35331 risultati

VulnerabilitàAlta
CVE-2026-40033 (CVSS 8.8)

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

NVD (NIST)26 mag 2026
News
Micropatches released for Windows Netlogon Remote Code Execution Vulnerability (CVE-2026-41089)

Micropatches released for Windows Netlogon Remote Code Execution Vulnerability (CVE-2026-41089) May 2026 Windows Updates brought a patch for CVE-2026-41089, a remotely exploitable issue on Windows Server acting as a domain controller. Under certain conditions, an unauthenticated attacker in loca ... Read more Published Date: May 26, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-41089

CVEfeed Newsroom26 mag 2026
VulnerabilitàAlta
CVE-2026-9544 (CVSS 7.3)

A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the file /api/Dinner/PayConfig. Performing a manipulation of the argument tableno results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)26 mag 2026
VulnerabilitàCritica
CVE-2026-9543 (CVSS 9.8)

A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

NVD (NIST)26 mag 2026
VulnerabilitàAlta
CVE-2026-9542 - CodeAstro Leave Management System add_staff.php sql injection

CVE ID :CVE-2026-9542 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9541 - Squirrel Cnut File sqobject.cpp ReadObject heap-based overflow

CVE ID :CVE-2026-9541 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9540 - vllm-project vllm OpenAI-compatible Serving Path denial of service

CVE ID :CVE-2026-9540 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-8174 - Cross-site Request Forgery

CVE ID :CVE-2026-8174 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-8479 - IEC 60870-5-104 Denial of Service Null Pointer Dereferencing

CVE ID :CVE-2026-8479 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :IEC 60870-5-104 used in bidirectional mode is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàCritica
CVE-2026-7374 (CVSS 9.9)

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

NVD (NIST)26 mag 2026
VulnerabilitàAlta
CVE-2026-7310 - HiDraw XML Parser Heap-Based Buffer Overflow Vulnerability

CVE ID :CVE-2026-7310 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance

CVE ID :CVE-2026-48136 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC). Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026

Pagina 1419 di 2945

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.