Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35476 risultati

VulnerabilitàAlta
CVE-2026-9291 - Insecure Deserialization in Amazon Braket SDK Job Results Processing

CVE ID :CVE-2026-9291 Published : May 22, 2026, 6:12 p.m. | 2 hours, 7 minutes ago Description :Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
Ubiquiti Patches Critical UniFi OS Vulnerabilities Allowing Remote Privilege Escalation

Ubiquiti Patches Critical UniFi OS Vulnerabilities Allowing Remote Privilege Escalation Ubiquiti Networks has released urgent security updates to address a series of highly critical vulnerabilities affecting its UniFi OS platform. These severe flaws could allow unauthenticated, remote at ... Read more Published Date: May 22, 2026 (3 days, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34911 CVE-2026-34910 CVE-2026-34909 CVE-2026-34908 CVE-2026-33000

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-39970 - TypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Picture Form

CVE ID :CVE-2026-39970 Published : May 22, 2026, 5:55 p.m. | 2 hours, 24 minutes ago Description :TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload form. The application fails to sanitize or restrict SVG/XML-based uploads and directly renders them when accessed through the domain. By uploading a crafted malicious SVG file containing embedded JavaScript, an attacker will execute arbitrary JavaScript code. This vulnerability directly enables stored XSS exploitation because the payload is persistently stored on your infrastructure (app.typebot.io) and accessible from a public-facing, permanent link. Stored XSS via malicious SVG uploads to app.typebot.io allows attackers to execute arbitrary JavaScript in victims' browsers, enabling session/token theft, account takeover, and exfiltration of sensitive user data. This issue has been fixed in version 3.16.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-39965 - TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks

CVE ID :CVE-2026-39965 Published : May 22, 2026, 5:27 p.m. | 2 hours, 52 minutes ago Description :TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block validate the initial request URL via validateHttpReqUrl() to block private IPs and cloud metadata hostnames. However, the HTTP clients (ky and fetch) follow 302 redirects without re-validating the redirect destination. An authenticated user can point a bot block to an attacker-controlled server that responds with a redirect to an internal IP, causing the Typebot server to reach internal services. An authenticated Typebot user can reach AWS metadata (169.254.169.254), private subnets, and container-internal services. Exploitable to extract cloud IAM credentials or probe internal APIs inaccessible from the internet. This issue has been fixed in version 3.16.0. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-39964 - TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers

CVE ID :CVE-2026-39964 Published : May 22, 2026, 5:21 p.m. | 2 hours, 58 minutes ago Description :TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme. A bot author can set a link URL to javascript:PAYLOAD, which executes in the visitor's browser context when clicked. Since the viewer is typically embedded in a third-party site, the attacker's JavaScript runs in the host page's origin and can exfiltrate cookies and session tokens. This can result in any authenticated Typebot user (including those on the free tier) being able to create a bot with this payload. Shared bots are publicly accessible — no victim authentication is required. This issue has been resolved in version 3.16.0. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
Breaking down the new Qualcomm chip vulnerability | Kaspersky official blog

Breaking down the new Qualcomm chip vulnerability | Kaspersky official blog Imagine handing your smartphone over for repair. A couple of days later, you pick it up — and great, it’s working again! But you won’t even realize that your device has been injected with malicious co ... Read more Published Date: May 22, 2026 (3 days, 10 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-34207 - TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation

CVE ID :CVE-2026-34207 Published : May 22, 2026, 5:12 p.m. | 3 hours, 7 minutes ago Description :TypeBot is a chatbot builder tool. SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked hostname literals, and literal IP formats. It does not resolve DNS before allowing the request. As a result, a hostname such as ssrf-repro.example that resolves to 127.0.0.1, 169.254.169.254, or RFC1918/private space passes validation and is later fetched by the backend HTTP client. This enables server-side request forgery to loopback, cloud metadata, and private network targets. This issue has been resolved in version 3.16.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-32253 - Sunshine: Authentication bypass via improper client certificate validation

CVE ID :CVE-2026-32253 Published : May 22, 2026, 5:07 p.m. | 3 hours, 13 minutes ago Description :Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints. This issue has been fixed in version 2026.516.143833. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-33712 - TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls

CVE ID :CVE-2026-33712 Published : May 22, 2026, 4:50 p.m. | 3 hours, 30 minutes ago Description :Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side code blocks. The fetch function exposed inside the isolated-vm sandbox calls Node.js native fetch without the SSRF validation (validateHttpReqUrl) that protects the HTTP Request block. This bypasses all SSRF mitigations added after GHSA-8gq9-rw7v-3jpr. Exploitation of this unauthenticated SSRF vulnerability can lead to cloud credential theft, internal network access and data exfiltration for any self-hosted Typebot deployments and hosted services. This issue has been fixed in version 3.16.0. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI

CVE ID :CVE-2026-9255 Published : May 22, 2026, 4:38 p.m. | 3 hours, 42 minutes ago Description :Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog

CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, tracked as CVE-2025-34291, to its Known Exploited Vulnerabilities (KEV) Catalog, signaling ... Read more Published Date: May 22, 2026 (2 days, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-34291

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-28735 - GitHub OAuth Scope Validation

CVE ID :CVE-2026-28735 Published : May 22, 2026, 4:26 p.m. | 1 hour, 53 minutes ago Description :Mattermost versions 11.6.x Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026

Pagina 1465 di 2957

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.