Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35376 risultati

VulnerabilitàAlta
CVE-2026-9353 - NousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py injection

CVE ID :CVE-2026-9353 Published : May 24, 2026, 3:45 a.m. | 6 hours, 46 minutes ago Description :A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Multi-Word Prompt Handler. The manipulation of the argument THREAT_PATTERNS leads to injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-3515 - Argument Injection in prefecthq/prefect

CVE ID :CVE-2026-3515 Published : May 24, 2026, 3:32 a.m. | 6 hours, 59 minutes ago Description :A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, leading to potential Server-Side Request Forgery (SSRF), credential theft, or remote code execution (RCE). The vulnerability affects both the `aget_directory()` and `get_directory()` methods in `src/integrations/prefect-github/prefect_github/repository.py`. This issue does not affect the GitLab and BitBucket integrations, which use a safer list-based command construction approach. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-9352 - NousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosure

CVE ID :CVE-2026-9352 Published : May 24, 2026, 3:30 a.m. | 7 hours, 1 minute ago Description :A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environments/local.py of the component Messaging Gateway Handler. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-9351 - NousResearch hermes-agent read_file Tool file_tools.py _is_blocked_device path traversal

CVE ID :CVE-2026-9351 Published : May 24, 2026, 3:15 a.m. | 7 hours, 16 minutes ago Description :A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16. This vulnerability affects the function _is_blocked_device of the file tools/file_tools.py of the component read_file Tool. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-9350 - NousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorization

CVE ID :CVE-2026-9350 Published : May 24, 2026, 2:45 a.m. | 7 hours, 46 minutes ago Description :A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py of the component Batch Runner. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-9349 - calcom cal.diy Generic React API bookings-single-view.getServerSideProps.tsx getServerSideProps information disclosure

CVE ID :CVE-2026-9349 Published : May 24, 2026, 2:30 a.m. | 6 hours, 1 minute ago Description :A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/bookings/views/bookings-single-view.getServerSideProps.tsx of the component Generic React API. This manipulation of the argument cancelledBy/rescheduledBy causes information disclosure. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-48829 - Apache GNU SASL NULL Pointer Dereference Vulnerability

CVE ID :CVE-2026-48829 Published : May 24, 2026, 2:22 a.m. | 6 hours, 9 minutes ago Description :In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-9348 - Edimax EW-7438RPn webs mp stack-based overflow

CVE ID :CVE-2026-9348 Published : May 24, 2026, 2:15 a.m. | 6 hours, 16 minutes ago Description :A vulnerability was found in Edimax EW-7438RPn up to 1.31. Affected by this vulnerability is an unknown functionality of the file /goform/mp of the component webs. The manipulation of the argument webs results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-9347 - Edimax EW-7438RPn webs formWizSurvey os command injection

CVE ID :CVE-2026-9347 Published : May 24, 2026, 1:30 a.m. | 7 hours, 1 minute ago Description :A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the component webs. The manipulation of the argument ip/mask/gateway leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-9346 - Edimax EW-7438RPn webs formWirelessTbl buffer overflow

CVE ID :CVE-2026-9346 Published : May 24, 2026, 12:30 a.m. | 8 hours, 1 minute ago Description :A flaw has been found in Edimax EW-7438RPn up to 1.31. This impacts the function formWirelessTbl of the file /goform/formWirelessTbl of the component webs. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-9345 - Edimax EW-7438RPn webs formWizSurvey buffer overflow

CVE ID :CVE-2026-9345 Published : May 24, 2026, 12:15 a.m. | 8 hours, 16 minutes ago Description :A vulnerability was detected in Edimax EW-7438RPn up to 1.31. This affects the function formWizSurvey of the file /goform/formWizSurvey of the component webs. Performing a manipulation of the argument ssid/manualssid/ip/mask/gateway results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026
VulnerabilitàAlta
CVE-2026-9344 - Edimax EW-7438RPn webs formWpsStart stack-based overflow

CVE ID :CVE-2026-9344 Published : May 24, 2026, midnight | 8 hours, 31 minutes ago Description :A security vulnerability has been detected in Edimax EW-7438RPn up to 1.31. The impacted element is an unknown function of the file /goform/formWpsStart of the component webs. Such manipulation of the argument pinCode/wlan-url leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mag 2026

Pagina 1448 di 2948

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.