Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35616 risultati

News
The Good, the Bad and the Ugly in Cybersecurity – Week 21

The Good, the Bad and the Ugly in Cybersecurity – Week 21 The Good | Joint Operations Dismantle Cybercrime Infrastructure, Infostealers & Malicious VPNs Over 200 individuals and another 382 suspects have been rounded up in Interpol’s Operation Ramz, an initi ... Read more Published Date: May 22, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-27136 - Invoking duplicate attributes can cause XSS in golang.org/x/net/html

CVE ID :CVE-2026-27136 Published : May 22, 2026, 3:01 p.m. | 3 hours, 18 minutes ago Description :Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-25681 - Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

CVE ID :CVE-2026-25681 Published : May 22, 2026, 3:01 p.m. | 3 hours, 18 minutes ago Description :Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-42506 - Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

CVE ID :CVE-2026-42506 Published : May 22, 2026, 3:01 p.m. | 1 hour, 18 minutes ago Description :Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-25680 - Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

CVE ID :CVE-2026-25680 Published : May 22, 2026, 3:01 p.m. | 3 hours, 18 minutes ago Description :Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-42502 - Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

CVE ID :CVE-2026-42502 Published : May 22, 2026, 3:01 p.m. | 3 hours, 18 minutes ago Description :Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-39821 - Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVE ID :CVE-2026-39821 Published : May 22, 2026, 3:01 p.m. | 1 hour, 18 minutes ago Description :The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2022-34363 - Dell Unisphere for PowerMax Authorization Bypass Vulnerability

CVE ID :CVE-2022-34363 Published : May 22, 2026, 2:44 p.m. | 1 hour, 35 minutes ago Description :Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2022-31231 - Dell ECS Improper Access Control Vulnerability

CVE ID :CVE-2022-31231 Published : May 22, 2026, 2:31 p.m. | 1 hour, 48 minutes ago Description :Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8992 - Ivanti Secure Access Client Certificate Validation Remote Code Execution

CVE ID :CVE-2026-8992 Published : May 22, 2026, 2:24 p.m. | 1 hour, 54 minutes ago Description :An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8353 - Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme

CVE ID :CVE-2026-8353 Published : May 22, 2026, 2:18 p.m. | 2 hours, 1 minute ago Description :Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting. Severity: 2.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2021-21508 - Dell VxRail Plain-text Password Storage Vulnerability

CVE ID :CVE-2021-21508 Published : May 22, 2026, 2:17 p.m. | 2 hours, 2 minutes ago Description :Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026

Pagina 1479 di 2968

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.