Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

764 risultati

VulnerabilitàAlta
CVE-2026-2302 - Unsafe Reflection in Mongoid::Criteria.from_hash

CVE ID : CVE-2026-2302 Published : Feb. 10, 2026, 7:16 p.m. | 1 hour, 6 minutes ago Description : Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-25610 - Invalid $geoNear index hint may cause server crash

CVE ID : CVE-2026-25610 Published : Feb. 10, 2026, 7:16 p.m. | 1 hour, 6 minutes ago Description : An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-26009 - Catalyst Affected by Remote Code Execution as Root via Containerized Install Script Execution

CVE ID : CVE-2026-26009 Published : Feb. 10, 2026, 7:16 p.m. | 1 hour, 6 minutes ago Description : Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating system as root via bash -c, with no sandboxing or containerization. Any user with template.create or template.update permission can define arbitrary shell commands that achieve full root-level remote code execution on every node machine in the cluster. This vulnerability is fixed in commit 11980aaf3f46315b02777f325ba02c56b110165d. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-25506 - MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery

CVE ID : CVE-2026-25506 Published : Feb. 10, 2026, 7:16 p.m. | 1 hour, 6 minutes ago Description : MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-25609 - profile command may permit unauthorized configuration

CVE ID : CVE-2026-25609 Published : Feb. 10, 2026, 7:16 p.m. | 1 hour, 6 minutes ago Description : Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-21355 - DNG SDK | Out-of-bounds Read (CWE-125)

CVE ID : CVE-2026-21355 Published : Feb. 10, 2026, 7:15 p.m. | 1 hour, 6 minutes ago Description : DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-21354 - DNG SDK | Integer Overflow or Wraparound (CWE-190)

CVE ID : CVE-2026-21354 Published : Feb. 10, 2026, 7:15 p.m. | 1 hour, 6 minutes ago Description : DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-21353 - DNG SDK | Integer Overflow or Wraparound (CWE-190)

CVE ID : CVE-2026-21353 Published : Feb. 10, 2026, 7:15 p.m. | 1 hour, 6 minutes ago Description : DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-21352 - DNG SDK | Out-of-bounds Write (CWE-787)

CVE ID : CVE-2026-21352 Published : Feb. 10, 2026, 7:15 p.m. | 1 hour, 6 minutes ago Description : DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-21346 - Bridge | Out-of-bounds Write (CWE-787)

CVE ID : CVE-2026-21346 Published : Feb. 10, 2026, 7:15 p.m. | 1 hour, 6 minutes ago Description : Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-21345 - Substance3D - Stager | Out-of-bounds Read (CWE-125)

CVE ID : CVE-2026-21345 Published : Feb. 10, 2026, 7:15 p.m. | 1 hour, 6 minutes ago Description : Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa
VulnerabilitàAlta
CVE-2026-21347 - Bridge | Integer Overflow or Wraparound (CWE-190)

CVE ID : CVE-2026-21347 Published : Feb. 10, 2026, 7:15 p.m. | 1 hour, 6 minutes ago Description : Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22h fa

Pagina 15 di 64

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.