Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35338 risultati

VulnerabilitàAlta
CVE-2026-9541 - Squirrel Cnut File sqobject.cpp ReadObject heap-based overflow

CVE ID :CVE-2026-9541 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9540 - vllm-project vllm OpenAI-compatible Serving Path denial of service

CVE ID :CVE-2026-9540 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-8174 - Cross-site Request Forgery

CVE ID :CVE-2026-8174 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-8479 - IEC 60870-5-104 Denial of Service Null Pointer Dereferencing

CVE ID :CVE-2026-8479 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :IEC 60870-5-104 used in bidirectional mode is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàCritica
CVE-2026-7374 (CVSS 9.9)

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

NVD (NIST)26 mag 2026
VulnerabilitàAlta
CVE-2026-7310 - HiDraw XML Parser Heap-Based Buffer Overflow Vulnerability

CVE ID :CVE-2026-7310 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests

CVE ID :CVE-2026-48135 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance

CVE ID :CVE-2026-48136 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC). Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero

CVE ID :CVE-2026-48131 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality). Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion

CVE ID :CVE-2026-48133 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-48134 - SQL injection issue in UserCheck Portal when DLP Software Blade is active

CVE ID :CVE-2026-48134 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-48132 - VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP

CVE ID :CVE-2026-48132 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic). Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026

Pagina 1420 di 2945

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.