News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
35791 risultati
CVE ID :CVE-2025-71212 Published : May 21, 2026, 2:16 p.m. | 2 hours, 1 minute ago Description :A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA adds Seven Vulnerabilities to KEV Catalog May 21, 2026CISA has added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation. The batch spans Microsoft Windows, Microsoft I ... Read more Published Date: May 21, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091 CVE-2010-0806 CVE-2010-0249 CVE-2009-3459 CVE-2009-1537 CVE-2008-4250
Autonomous fuzzing process under LLM supervision The CCN project is co-financed by the European Regional Development Fund and the State Budget under the European Funds for Digital Development Programme 2021-2027. Fuzzing is an automated software tes ... Read more Published Date: May 21, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42268 CVE-2026-35251
P2PInfect Botnet Compromises Kubernetes Clusters Through Exposed Redis Instances A well-known botnet is now targeting cloud environments in a more calculated way than before. P2PInfect, a Rust-written peer-to-peer malware active since mid-2023, has been observed compromising Kuber ... Read more Published Date: May 21, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-46333 CVE-2022-0543
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week starts small.A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not alway ... Read more Published Date: May 21, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on the ... Read more Published Date: May 21, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091 CVE-2026-42897 CVE-2026-41940 CVE-2010-0806 CVE-2010-0249 CVE-2009-3459 CVE-2009-1537 CVE-2008-4250
Vulnerability in Request Tracker software Vulnerability in Request Tracker software CVE ID CVE-2026-6841 Publication date 21 May 2026 Vendor Best Practical Product Request Tracker Vulnerable versions From 5.0.4 below 5.0.10From 6.0.0 below 6. ... Read more Published Date: May 21, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-6841
CVE ID :CVE-2026-43494 Published : May 21, 2026, 10:49 a.m. | 1 hour, 28 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user(). Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-0393 Published : May 21, 2026, 10:44 a.m. | 1 hour, 33 minutes ago Description :The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Zeer kritiek Drupal-lek maakt SQL Injection mogelijk, updates beschikbaar Een zeer kritieke kwetsbaarheid in het contentmanagementsysteem (CMS) Drupal maakt SQL Injection mogelijk. Daardoor kunnen aanvallers toegang tot informatie krijgen. In bepaalde gevallen kan een aanva ... Read more Published Date: May 21, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9082
MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability
CVE ID :CVE-2026-28764 Published : May 21, 2026, 10:16 a.m. | 2 hours, 1 minute ago Description :MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1511 di 2983