Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35673 risultati

News
Drupal meldt actief misbruik van zeer kritiek SQL Injection-lek

Drupal meldt actief misbruik van zeer kritiek SQL Injection-lek De ontwikkelaars van het contentmanagementsysteem (CMS) Drupal waarschuwen voor actief misbruik van een zeer kritiek SQL Injection-lek (CVE-2026-9082). Via de kwetsbaarheid kan een aanvaller toegang t ... Read more Published Date: May 22, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9082

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2025-26483 - Dell PowerFlex Manager Open Redirect Vulnerability

CVE ID :CVE-2025-26483 Published : May 22, 2026, 1:33 p.m. | 46 minutes ago Description :Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8997 - Heap Buffer Overflow in vifm

CVE ID :CVE-2026-8997 Published : May 22, 2026, 1:26 p.m. | 53 minutes ago Description :vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length of history entries in release builds, potentially allowing a crafted long path or command in the history to cause memory corruption or application crashes. Releases from 0.12.1 to 0.14.3 (including) are considered vulnerable. This issue was fixed in commit 23063c7 Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
Securing AI systems without overconfidence or fear – Part 2: Attack surfaces and the checkpoint flow

Securing AI systems without overconfidence or fear – Part 2: Attack surfaces and the checkpoint flow Document information Series Securing AI systems without overconfidence or fear Part 2 of 5 Title Attack surfaces and the checkpoint flow Date May 2026 Author Hussein Bahmad (NVISO) Reading time ~13 mi ... Read more Published Date: May 22, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-32711

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2025-32745 - Dell PowerFlex Manager Certificate Validation Weakness

CVE ID :CVE-2025-32745 Published : May 22, 2026, 1:23 p.m. | 56 minutes ago Description :Dell PowerFlex Manager, version(s) Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-9277 - shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`

CVE ID :CVE-2026-9277 Published : May 22, 2026, 1:22 p.m. | 57 minutes ago Description :shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\n...' }` from external input, and (2) via `parse(cmd, envFn)` when `envFn` returns object tokens whose `.op` is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: `.op` must match the parser's control-operator allowlist; `{ op: 'glob', pattern }` validates `pattern` and forbids line terminators; `{ comment }` validates `comment` and forbids line terminators; any other object shape throws `TypeError`. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8673 - Password re-initialization mechanism sends passwords in plain text

CVE ID :CVE-2026-8673 Published : May 22, 2026, 1:18 p.m. | 1 hour, 1 minute ago Description :Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8672 - Default credentials for internal DB

CVE ID :CVE-2026-8672 Published : May 22, 2026, 1:17 p.m. | 1 hour, 2 minutes ago Description :Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: before 25.3.0. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8671 - Log Files contain encrypted secrets

CVE ID :CVE-2026-8671 Published : May 22, 2026, 1:15 p.m. | 1 hour, 4 minutes ago Description :Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2025-32746 - Dell PowerFlex Manager Insecure Storage of Sensitive Information Vulnerability

CVE ID :CVE-2025-32746 Published : May 22, 2026, 1:13 p.m. | 1 hour, 6 minutes ago Description :Dell PowerFlex Manager, version(s) Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8670 - Insecure session handling on metrics web server

CVE ID :CVE-2026-8670 Published : May 22, 2026, 1:12 p.m. | 1 hour, 6 minutes ago Description :Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This issue affects Avantra: before 25.3.1. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2025-32747 - Dell PowerFlex Manager Privilege Elevation Vulnerability

CVE ID :CVE-2025-32747 Published : May 22, 2026, 1:02 p.m. | 1 hour, 17 minutes ago Description :Dell PowerFlex Manager, version(s) Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026

Pagina 1485 di 2973

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.