Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35415 risultati

VulnerabilitàAlta
CVE-2026-9306 - QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization

CVE ID :CVE-2026-9306 Published : May 23, 2026, 3 p.m. | 9 hours, 31 minutes ago Description :A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9305 - QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection

CVE ID :CVE-2026-9305 Published : May 23, 2026, 2:30 p.m. | 10 hours, 1 minute ago Description :A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9304 - calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery

CVE ID :CVE-2026-9304 Published : May 23, 2026, 1:45 p.m. | 10 hours, 46 minutes ago Description :A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9303 - calcom cal.diy cross-site request forgery

CVE ID :CVE-2026-9303 Published : May 23, 2026, 1:30 p.m. | 9 hours, 1 minute ago Description :A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9302 - 546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection

CVE ID :CVE-2026-9302 Published : May 23, 2026, 1:15 p.m. | 9 hours, 16 minutes ago Description :A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/command/VpsTest.php of the component VpsTest Console. Executing a manipulation of the argument vf can lead to code injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9301 - omec-project amf NGReset Message memory corruption

CVE ID :CVE-2026-9301 Published : May 23, 2026, 1 p.m. | 7 hours, 31 minutes ago Description :A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. It is recommended to apply a patch to fix this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
News
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the ... Read more Published Date: May 23, 2026 (3 days, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897 CVE-2026-41940 CVE-2026-5194

CVEfeed Newsroom23 mag 2026
News
Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now!

Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now! A newly disclosed flaw in one of the world’s most widely deployed web servers is forcing administrators into another emergency patch cycle. Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolsl ... Read more Published Date: May 23, 2026 (3 days, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9256 CVE-2026-42945

CVEfeed Newsroom23 mag 2026
VulnerabilitàAlta
CVE-2026-9300 - omec-project amf NGSetupRequest memory corruption

CVE ID :CVE-2026-9300 Published : May 23, 2026, 11:45 a.m. | 6 hours, 46 minutes ago Description :A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to memory corruption. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. It is best practice to apply a patch to resolve this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-46300 - net: skbuff: preserve shared-frag marker during coalescing

CVE ID :CVE-2026-46300 Published : May 23, 2026, 11:44 a.m. | 6 hours, 47 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header() after copying frag descriptors, but that helper only carries over gso_{size,segs, type} and never touches skb_shinfo()->flags; skb_shift() moves frag descriptors directly and leaves flags untouched. As a result, the destination skb keeps a reference to the same externally-owned or page-cache-backed pages while reporting skb_has_shared_frag() as false. The mismatch is harmful in any in-place writer that uses skb_has_shared_frag() to decide whether shared pages must be detoured through skb_cow_data(). ESP input is one such writer (esp4.c, esp6.c), and a single nft 'dup to ' rule -- or any other nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d skb in esp_input() with the marker stripped, letting an unprivileged user write into the page cache of a root-owned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors were actually moved from the source. skb_copy() and skb_copy_expand() share skb_copy_header() too but linearize all paged data into freshly allocated head storage and emerge with nr_frags == 0, so skb_has_shared_frag() returns false on its own; they need no change. The same omission exists in skb_gro_receive() and skb_gro_receive_list(). The former moves the incoming skb's frag descriptors into the accumulator's last sub-skb via two paths (a direct frag-move loop and the head_frag + memcpy path); the latter chains the incoming skb whole onto p's frag_list. Downstream skb_segment() reads only sk...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-43503 - net: skbuff: propagate shared-frag marker through frag-transfer helpers

CVE ID :CVE-2026-43503 Published : May 23, 2026, 11:44 a.m. | 6 hours, 47 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9299 - omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption

CVE ID :CVE-2026-9299 Published : May 23, 2026, 11 a.m. | 7 hours, 31 minutes ago Description :A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIndication of the file /go/src/amf/ngap/handler.go. This manipulation causes memory corruption. Remote exploitation of the attack is possible. The exploit has been published and may be used. Applying a patch is the recommended action to fix this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026

Pagina 1454 di 2952

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.