Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35356 risultati

News
Vulnerability in Kenik cameras software

Vulnerability in Kenik cameras software Vulnerability in Kenik cameras software CVE ID CVE-2026-7766 Publication date 25 May 2026 Vendor Kenik Product KG-5230TAS-IL-3, KG-5230TAS-IL-G3, KG-5230DAS-IL-G3, KG-5260TZAS-IL-3, KG-5260DZAS-IL-3, ... Read more Published Date: May 25, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-7766

CVEfeed Newsroom25 mag 2026
VulnerabilitàAlta
CVE-2026-9455 - Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection

CVE ID :CVE-2026-9455 Published : May 25, 2026, 11:45 a.m. | 46 minutes ago Description :A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument FileName leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9454 - Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection

CVE ID :CVE-2026-9454 Published : May 25, 2026, 11:30 a.m. | 1 hour, 1 minute ago Description :A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-7766 - Path Traversal in Kenik cameras

CVE ID :CVE-2026-7766 Published : May 25, 2026, 11:16 a.m. | 1 hour, 15 minutes ago Description :Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server. The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras. Rest of the products were fixed in version 2025-04-21. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9453 - FoundDream miniclawd SkillsLoader skills-loader.ts which command injection

CVE ID :CVE-2026-9453 Published : May 25, 2026, 11:15 a.m. | 1 hour, 16 minutes ago Description :A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src/application/skills-loader.ts of the component SkillsLoader. Performing a manipulation of the argument requires.bins results in command injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9452 - FoundDream miniclawd exec.ts ExecTool.execute os command injection

CVE ID :CVE-2026-9452 Published : May 25, 2026, 11 a.m. | 1 hour, 31 minutes ago Description :A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
News
Vulnerability in Lifetime software

Vulnerability in Lifetime software Vulnerability in Lifetime software CVE ID CVE-2026-40127 Publication date 25 May 2026 Vendor OutSystems Product Lifetime Vulnerable versions All before 11.28.2.3955 Vulnerability type (CWE) Authorizat ... Read more Published Date: May 25, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom25 mag 2026
News
Hackers Actives Scanning SonicWall Firewall Interfaces – 597,000 Sessions Observed

Hackers Actives Scanning SonicWall Firewall Interfaces – 597,000 Sessions Observed A sharp rise in internet-wide scanning activity targeting SonicWall firewall management interfaces has been detected, raising concerns about a potential pre-disclosure reconnaissance phase tied to new ... Read more Published Date: May 25, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-0400

CVEfeed Newsroom25 mag 2026
VulnerabilitàAlta
CVE-2026-9451 - code-projects Employee Management System applyleaveprocess.php sql injection

CVE ID :CVE-2026-9451 Published : May 25, 2026, 10:45 a.m. | 1 hour, 46 minutes ago Description :A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-46745 - Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token

CVE ID :CVE-2026-46745 Published : May 25, 2026, 10:41 a.m. | 1 hour, 50 minutes ago Description :Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9450 - code-projects Employee Management System psubmit.php sql injection

CVE ID :CVE-2026-9450 Published : May 25, 2026, 10:30 a.m. | 2 hours, 1 minute ago Description :A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-40127 - Authorization Bypass Through User-Controlled Key in OutSystems Lifetime

CVE ID :CVE-2026-40127 Published : May 25, 2026, 10:18 a.m. | 2 hours, 13 minutes ago Description :OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime version 11.28.2.3955 Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026

Pagina 1436 di 2947

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.