Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35458 risultati

VulnerabilitàAlta
CVE-2026-34207 - TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation

CVE ID :CVE-2026-34207 Published : May 22, 2026, 5:12 p.m. | 3 hours, 7 minutes ago Description :TypeBot is a chatbot builder tool. SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked hostname literals, and literal IP formats. It does not resolve DNS before allowing the request. As a result, a hostname such as ssrf-repro.example that resolves to 127.0.0.1, 169.254.169.254, or RFC1918/private space passes validation and is later fetched by the backend HTTP client. This enables server-side request forgery to loopback, cloud metadata, and private network targets. This issue has been resolved in version 3.16.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-32253 - Sunshine: Authentication bypass via improper client certificate validation

CVE ID :CVE-2026-32253 Published : May 22, 2026, 5:07 p.m. | 3 hours, 13 minutes ago Description :Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints. This issue has been fixed in version 2026.516.143833. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-33712 - TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls

CVE ID :CVE-2026-33712 Published : May 22, 2026, 4:50 p.m. | 3 hours, 30 minutes ago Description :Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side code blocks. The fetch function exposed inside the isolated-vm sandbox calls Node.js native fetch without the SSRF validation (validateHttpReqUrl) that protects the HTTP Request block. This bypasses all SSRF mitigations added after GHSA-8gq9-rw7v-3jpr. Exploitation of this unauthenticated SSRF vulnerability can lead to cloud credential theft, internal network access and data exfiltration for any self-hosted Typebot deployments and hosted services. This issue has been fixed in version 3.16.0. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI

CVE ID :CVE-2026-9255 Published : May 22, 2026, 4:38 p.m. | 3 hours, 42 minutes ago Description :Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog

CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, tracked as CVE-2025-34291, to its Known Exploited Vulnerabilities (KEV) Catalog, signaling ... Read more Published Date: May 22, 2026 (2 days, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-34291

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-28735 - GitHub OAuth Scope Validation

CVE ID :CVE-2026-28735 Published : May 22, 2026, 4:26 p.m. | 1 hour, 53 minutes ago Description :Mattermost versions 11.6.x Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-28445 - Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview

CVE ID :CVE-2026-28445 Published : May 22, 2026, 4:12 p.m. | 2 hours, 7 minutes ago Description :Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via Solid's innerHTML directive without any sanitization, even though DOMPurify is already a dependency and is used elsewhere in the codebase (e.g., StreamingBubble.tsx). Because rating blocks are not flagged as isUnsafe by the import sanitizer and the builder preview renders bots inline on the builder's own origin (builder.typebot.io) under a CSP permitting 'unsafe-inline', a malicious imported or collaborator-crafted typebot can execute arbitrary HTML/JS in the builder's authenticated context, bypassing the Web Worker sandbox that protects Script blocks during preview. This allows session hijacking and privilege escalation within the builder application. This issue has been fixed in version 3.16.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
CISA Warns of Microsoft Defender 0-Day Vulnerabilities Exploited in Attacks

CISA Warns of Microsoft Defender 0-Day Vulnerabilities Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Microsoft Defender vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations o ... Read more Published Date: May 22, 2026 (2 days, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-28444 - Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure

CVE ID :CVE-2026-28444 Published : May 22, 2026, 4 p.m. | 2 hours, 19 minutes ago Description :Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId but fetches logs solely by resultId without verifying that the result belongs to the authorized typebot, leading to IDOR. An authenticated attacker can supply their own typebotId alongside any victim's resultId to read execution logs from other workspaces, leaking sensitive data including HTTP response bodies, AI model outputs, and webhook payloads. Every other result-scoped endpoint in the same router properly validates that the resultId belongs to the authorized typebotId. This confirms the missing check is an oversight, not a design choice. This issue has been fixed in version 3.15.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
CISA adds Langflow and Trend Micro Apex One to KEV

CISA adds Langflow and Trend Micro Apex One to KEV May 22, 2026CVE-2025-34291 — Langflow Origin Validation Error (RCE)CVSS: 9.4CWE: CWE-346 — Origin Validation ErrorAffected Versions: Langflow ≤ 1.6.9Vulnerability SummaryResearchers at Obsidian Securi ... Read more Published Date: May 22, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34926 CVE-2026-20223 CVE-2025-34291

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-7325 - Devolutions Server Active Directory Browsing Authorization Bypass

CVE ID :CVE-2026-7325 Published : May 22, 2026, 3:30 p.m. | 2 hours, 49 minutes ago Description :Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-9251 - Devolutions Server Missing Authorization Vulnerability

CVE ID :CVE-2026-9251 Published : May 22, 2026, 3:29 p.m. | 2 hours, 50 minutes ago Description :Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow and gain access to an entry's data via a crafted status change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026

Pagina 1464 di 2955

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.