Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35561 risultati

VulnerabilitàAlta
CVE-2022-34363 - Dell Unisphere for PowerMax Authorization Bypass Vulnerability

CVE ID :CVE-2022-34363 Published : May 22, 2026, 2:44 p.m. | 1 hour, 35 minutes ago Description :Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2022-31231 - Dell ECS Improper Access Control Vulnerability

CVE ID :CVE-2022-31231 Published : May 22, 2026, 2:31 p.m. | 1 hour, 48 minutes ago Description :Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8992 - Ivanti Secure Access Client Certificate Validation Remote Code Execution

CVE ID :CVE-2026-8992 Published : May 22, 2026, 2:24 p.m. | 1 hour, 54 minutes ago Description :An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8353 - Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme

CVE ID :CVE-2026-8353 Published : May 22, 2026, 2:18 p.m. | 2 hours, 1 minute ago Description :Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting. Severity: 2.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2021-21508 - Dell VxRail Plain-text Password Storage Vulnerability

CVE ID :CVE-2021-21508 Published : May 22, 2026, 2:17 p.m. | 2 hours, 2 minutes ago Description :Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-9256 - NGINX ngx_http_rewrite_module vulnerability

CVE ID :CVE-2026-9256 Published : May 22, 2026, 2:11 p.m. | 2 hours, 8 minutes ago Description :NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8347 - Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog

CVE ID :CVE-2026-8347 Published : May 22, 2026, 2:06 p.m. | 2 hours, 13 minutes ago Description :Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog. This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting. Severity: 2.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
Vulnerability in vifm software

Vulnerability in vifm software Vulnerability in vifm software CVE ID CVE-2026-8997 Publication date 22 May 2026 Vendor vifm Product vifm Vulnerable versions From 0.12.1 through 0.14.3 Vulnerability type (CWE) Heap-based Buffer Over ... Read more Published Date: May 22, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-8997

CVEfeed Newsroom22 mag 2026
News
Drupal meldt actief misbruik van zeer kritiek SQL Injection-lek

Drupal meldt actief misbruik van zeer kritiek SQL Injection-lek De ontwikkelaars van het contentmanagementsysteem (CMS) Drupal waarschuwen voor actief misbruik van een zeer kritiek SQL Injection-lek (CVE-2026-9082). Via de kwetsbaarheid kan een aanvaller toegang t ... Read more Published Date: May 22, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9082

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2025-26483 - Dell PowerFlex Manager Open Redirect Vulnerability

CVE ID :CVE-2025-26483 Published : May 22, 2026, 1:33 p.m. | 46 minutes ago Description :Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8997 - Heap Buffer Overflow in vifm

CVE ID :CVE-2026-8997 Published : May 22, 2026, 1:26 p.m. | 53 minutes ago Description :vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length of history entries in release builds, potentially allowing a crafted long path or command in the history to cause memory corruption or application crashes. Releases from 0.12.1 to 0.14.3 (including) are considered vulnerable. This issue was fixed in commit 23063c7 Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
Securing AI systems without overconfidence or fear – Part 2: Attack surfaces and the checkpoint flow

Securing AI systems without overconfidence or fear – Part 2: Attack surfaces and the checkpoint flow Document information Series Securing AI systems without overconfidence or fear Part 2 of 5 Title Attack surfaces and the checkpoint flow Date May 2026 Author Hussein Bahmad (NVISO) Reading time ~13 mi ... Read more Published Date: May 22, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-32711

CVEfeed Newsroom22 mag 2026

Pagina 1475 di 2964

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.