Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35372 risultati

VulnerabilitàAlta
CVE-2026-9436 - Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection

CVE ID :CVE-2026-9436 Published : May 25, 2026, 7 a.m. | 3 hours, 31 minutes ago Description :A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
News
CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks

CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks CISA has issued an urgent alert regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited in real-world attacks. The flaw, classi ... Read more Published Date: May 25, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9082

CVEfeed Newsroom25 mag 2026
VulnerabilitàAlta
CVE-2026-9435 - Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection

CVE ID :CVE-2026-9435 Published : May 25, 2026, 6:45 a.m. | 3 hours, 46 minutes ago Description :A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9434 - Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection

CVE ID :CVE-2026-9434 Published : May 25, 2026, 6:30 a.m. | 4 hours, 1 minute ago Description :A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setWiFiWpsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument wscDisabled leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9433 - Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection

CVE ID :CVE-2026-9433 Published : May 25, 2026, 6:15 a.m. | 4 hours, 16 minutes ago Description :A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-2651 - Missing Authorization Validation in mlflow/mlflow

CVE ID :CVE-2026-2651 Published : May 25, 2026, 6 a.m. | 4 hours, 31 minutes ago Description :A vulnerability in MLflow versions Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9432 - Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection

CVE ID :CVE-2026-9432 Published : May 25, 2026, 6 a.m. | 4 hours, 31 minutes ago Description :A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setWiFiAdvancedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument bgProtection results in os command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-41863 - LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API

CVE ID :CVE-2026-41863 Published : May 25, 2026, 5:45 a.m. | 4 hours, 46 minutes ago Description :Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories. Affected versions: Spring AI: 1.1.0 through 1.1.x Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9431 - Tenda F1202 PptpUserAdd fromPptpUserAdd stack-based overflow

CVE ID :CVE-2026-9431 Published : May 25, 2026, 5:45 a.m. | 4 hours, 46 minutes ago Description :A vulnerability was identified in Tenda F1202 1.2.0.20(408). This affects the function fromPptpUserAdd of the file /goform/PptpUserAdd. The manipulation of the argument opttype leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9430 - Tenda F1202 GstDhcpSetSerof formGstDhcpSetSer stack-based overflow

CVE ID :CVE-2026-9430 Published : May 25, 2026, 5:30 a.m. | 3 hours, 1 minute ago Description :A vulnerability was determined in Tenda F1202 1.2.0.20(408). Affected by this issue is the function formGstDhcpSetSer of the file /goform/GstDhcpSetSerof. Executing a manipulation of the argument dips can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-25193 - Gallagher Command Centre Service Account Credentials Exposure

CVE ID :CVE-2026-25193 Published : May 25, 2026, 5:28 a.m. | 3 hours, 3 minutes ago Description :Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9429 - Tenda F1202 WrlExtraSet formWrlExtraSet stack-based overflow

CVE ID :CVE-2026-9429 Published : May 25, 2026, 5:15 a.m. | 3 hours, 16 minutes ago Description :A vulnerability was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. Performing a manipulation of the argument delno results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026

Pagina 1440 di 2948

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.