Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35338 risultati

VulnerabilitàAlta
CVE-2025-11482 - Allocation of Resources Without Limits or Throttling in the OPC-UA Server

CVE ID :CVE-2025-11482 Published : May 26, 2026, 2:16 p.m. | 15 minutes ago Description :An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attacker to permanently prevent legitimate users from interacting with the service. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-41917 - OpenKM 6.3.12 Local File Inclusion via Admin Scripting

CVE ID :CVE-2026-41917 Published : May 26, 2026, 2:08 p.m. | 23 minutes ago Description :OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying an attacker-controlled filesystem path through the fsPath parameter with action=Load. Attackers can exploit this to access sensitive files including /etc/passwd, configuration files containing database credentials, and JVM keystores accessible to the OpenKM process. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-41401 - libyang - Heap Use-After-Free Write in XML Metadata Parsing

CVE ID :CVE-2026-41401 Published : May 26, 2026, 2:08 p.m. | 23 minutes ago Description :libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
News
'WhatsApp-accounts op oudere iPhones gehackt via zeroclick-aanval'

'WhatsApp-accounts op oudere iPhones gehackt via zeroclick-aanval' In Italië zijn meerdere WhatsApp-gebruikers met een oudere iPhone het slachtoffer van een zeroclick-aanval geworden, zo meldt het Italiaanse forensisch onderzoeksbedrijf Forenser. Via de aanval kregen ... Read more Published Date: May 26, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-55177 CVE-2025-43300

CVEfeed Newsroom26 mag 2026
News
Microsoft SharePoint Server Vulnerability Enables Remote Code Execution Attacks

Microsoft SharePoint Server Vulnerability Enables Remote Code Execution Attacks Microsoft has disclosed a critical security vulnerability in SharePoint Server that could allow authenticated attackers to execute arbitrary code remotely across multiple versions of the platform. Tra ... Read more Published Date: May 26, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-26980

CVEfeed Newsroom26 mag 2026
News
Hackers Exploit Ghost CMS CVE-2026-26980 to Poison 700 Websites With ClickFix Malware

Hackers Exploit Ghost CMS CVE-2026-26980 to Poison 700 Websites With ClickFix Malware A critical SQL injection flaw in Ghost CMS has been weaponized by at least two threat actor groups to silently poison over 700 websites with ClickFix malware, putting unsuspecting visitors at serious ... Read more Published Date: May 26, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-26980

CVEfeed Newsroom26 mag 2026
News
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be m ... Read more Published Date: May 26, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-45585 CVE-2026-42945 CVE-2026-31635 CVE-2026-32201

CVEfeed Newsroom26 mag 2026
News
Apache CXF LDAP Injection Vulnerability Let Attacker Retrieve Arbitrary Certificates

Apache CXF LDAP Injection Vulnerability Let Attacker Retrieve Arbitrary Certificates A newly disclosed vulnerability in Apache CXF, tracked as CVE-2026-44930, is raising concerns among enterprise users relying on its XKMS (XML Key Management Specification) services. The flaw, classifi ... Read more Published Date: May 26, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-44930

CVEfeed Newsroom26 mag 2026
News
ConnectWise Automate Vulnerability Let Attackers Bypass Security Checks

ConnectWise Automate Vulnerability Let Attackers Bypass Security Checks ConnectWise has disclosed a high-impact security vulnerability in its Automate platform that could allow attackers to bypass critical security checks and execute malicious code under specific conditio ... Read more Published Date: May 26, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9089

CVEfeed Newsroom26 mag 2026
News
Critical Ghost CMS Vulnerability Exploited to Hack 700+ Websites

Critical Ghost CMS Vulnerability Exploited to Hack 700+ Websites A critical Ghost CMS vulnerability identified as CVE-2026-26980 has been exploited in a widespread cyber campaign that compromised more than 700 websites, including platforms associated with major ins ... Read more Published Date: May 26, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091 CVE-2026-26980

CVEfeed Newsroom26 mag 2026
VulnerabilitàAlta
CVE-2026-44410 - Function Abusement Vulnerability in ZTE ZXUniPOS NDS-LTE

CVE ID :CVE-2026-44410 Published : May 26, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks. Severity: 3.8 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-25104 - MediaArea MediaInfoLib LXF Parsing Heap Overflow

CVE ID :CVE-2026-25104 Published : May 26, 2026, 8:41 a.m. | 3 hours, 50 minutes ago Description :MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026

Pagina 1421 di 2945

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.