Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35791 risultati

VulnerabilitàAlta
CVE-2026-22880 - Mobile SSO authentication flow allows credential theft via malicious server

CVE ID :CVE-2026-22880 Published : May 21, 2026, 9:16 a.m. | 1 hour ago Description :Mattermost Mobile Apps versions Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-27349 - WordPress Mail Mint plugin <= 1.19.5 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-27349 Published : May 21, 2026, 9:16 a.m. | 1 hour ago Description :Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sensitive Data. This issue affects Mail Mint: from n/a through 1.19.5. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-45252 - Heap overflow in FUSE_LISTXATTR

CVE ID :CVE-2026-45252 Published : May 21, 2026, 10:16 a.m. | 2 hours, 1 minute ago Description :When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a packed list of NUL-terminated strings. The fusefs kernel module calls strlen() on this daemon-supplied buffer without first verifying that the entire list is NUL-terminated. If a malicious daemon sends a non-NUL-terminated list, the fusefs kernel module may read beyond the end of one heap-allocated buffer and potentially write beyond the end of a second buffer. A malicious daemon could disclose up to 253 bytes of kernel heap memory, or it could inject up to 250 attacker-controlled bytes into unallocated kernel heap space. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-45251 - Kernel use-after-free via file descriptor syscalls

CVE ID :CVE-2026-45251 Published : May 21, 2026, 10:16 a.m. | 2 hours, 1 minute ago Description :A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. Because the blocked thread does not hold a reference to the underlying object, this closure may result in the object being freed while the thread remains blocked. In this situation, the kernel must remove the blocked thread from the per-object wait queue prior to freeing the object. In the case of some file descriptor types, the kernel failed to unlink blocked threads from the object before freeing it. When the blocked thread is subsequently woken, it accesses memory that has already been freed resulting in a use-after-free vulnerability. The use-after-free vulnerability may be triggered by an unprivileged local user and can be exploited to obtain superuser privileges. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
News
Beveiligingslekken in Microsoft Defender actief misbruikt bij aanvallen

Beveiligingslekken in Microsoft Defender actief misbruikt bij aanvallen Aanvallers maken actief misbruik van twee kwetsbaarheden in Microsoft Defender, de antivirussoftware van Microsoft die onder andere in Windows is ingebouwd. Het techbedrijf heeft updates uitgerold om ... Read more Published Date: May 21, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091

CVEfeed Newsroom21 mag 2026
News
New NGINX 0-Day RCE “nginx-poolslip” Affects Millions of NGINX Servers

New NGINX 0-Day RCE “nginx-poolslip” Affects Millions of NGINX Servers A newly disclosed zero-day remote code execution (RCE) vulnerability, dubbed nginx-poolslip, has been identified in NGINX version 1.31.0, the latest stable release of the widely deployed web server so ... Read more Published Date: May 21, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42945

CVEfeed Newsroom21 mag 2026
News
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a ca ... Read more Published Date: May 21, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-46333 CVE-2026-42897 CVE-2026-41940

CVEfeed Newsroom21 mag 2026
VulnerabilitàAlta
CVE-2026-7836 - hextoint macro uppercase bug

CVE ID :CVE-2026-7836 Published : May 21, 2026, 7:35 a.m. | 41 minutes ago Description :In Netatalk 2.0.0 through 4.4.2, hextoint macro uppercase bug. Fixed in 4.5.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-7835 - Format string argument mismatch

CVE ID :CVE-2026-7835 Published : May 21, 2026, 7:35 a.m. | 42 minutes ago Description :In Netatalk 3.0.3 through 4.4.2, format string argument mismatch. Fixed in 4.5.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-44076 - Shell injection via volume path

CVE ID :CVE-2026-44076 Published : May 21, 2026, 7:35 a.m. | 42 minutes ago Description :In Netatalk 3.1.0 through 4.4.2, shell injection via volume path. Fixed in 4.4.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-44073 - seteuid failure ignored in auth modules

CVE ID :CVE-2026-44073 Published : May 21, 2026, 7:35 a.m. | 42 minutes ago Description :In Netatalk 1.5.0 through 4.4.2, seteuid failure ignored in auth modules. Fixed in 4.5.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-44072 - system() after failed chdir()

CVE ID :CVE-2026-44072 Published : May 21, 2026, 7:35 a.m. | 42 minutes ago Description :In Netatalk 2.2.1 through 4.4.2, system() after failed chdir(). Fixed in 4.5.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026

Pagina 1514 di 2983

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.