Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35818 risultati

VulnerabilitàAlta
CVE-2026-44074 - Bitwise OR of errno values

CVE ID :CVE-2026-44074 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor service disruption via conditions that trigger incorrect error-handling paths. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-44057 - Dead bounds check in Spotlight RPC unmarshaller

CVE ID :CVE-2026-44057 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC requests. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-27349 - WordPress Mail Mint plugin <= 1.19.5 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-27349 Published : May 21, 2026, 9:16 a.m. | 1 hour ago Description :Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sensitive Data. This issue affects Mail Mint: from n/a through 1.19.5. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-22880 - Mobile SSO authentication flow allows credential theft via malicious server

CVE ID :CVE-2026-22880 Published : May 21, 2026, 9:16 a.m. | 1 hour ago Description :Mattermost Mobile Apps versions Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-27393 - WordPress CF7 WOW Styler plugin <= 1.7.6 - Broken Access Control vulnerability

CVE ID :CVE-2026-27393 Published : May 21, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 WOW Styler: from n/a through 1.7.6. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-45252 - Heap overflow in FUSE_LISTXATTR

CVE ID :CVE-2026-45252 Published : May 21, 2026, 10:16 a.m. | 2 hours, 1 minute ago Description :When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a packed list of NUL-terminated strings. The fusefs kernel module calls strlen() on this daemon-supplied buffer without first verifying that the entire list is NUL-terminated. If a malicious daemon sends a non-NUL-terminated list, the fusefs kernel module may read beyond the end of one heap-allocated buffer and potentially write beyond the end of a second buffer. A malicious daemon could disclose up to 253 bytes of kernel heap memory, or it could inject up to 250 attacker-controlled bytes into unallocated kernel heap space. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-45251 - Kernel use-after-free via file descriptor syscalls

CVE ID :CVE-2026-45251 Published : May 21, 2026, 10:16 a.m. | 2 hours, 1 minute ago Description :A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. Because the blocked thread does not hold a reference to the underlying object, this closure may result in the object being freed while the thread remains blocked. In this situation, the kernel must remove the blocked thread from the per-object wait queue prior to freeing the object. In the case of some file descriptor types, the kernel failed to unlink blocked threads from the object before freeing it. When the blocked thread is subsequently woken, it accesses memory that has already been freed resulting in a use-after-free vulnerability. The use-after-free vulnerability may be triggered by an unprivileged local user and can be exploited to obtain superuser privileges. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
News
Beveiligingslekken in Microsoft Defender actief misbruikt bij aanvallen

Beveiligingslekken in Microsoft Defender actief misbruikt bij aanvallen Aanvallers maken actief misbruik van twee kwetsbaarheden in Microsoft Defender, de antivirussoftware van Microsoft die onder andere in Windows is ingebouwd. Het techbedrijf heeft updates uitgerold om ... Read more Published Date: May 21, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091

CVEfeed Newsroom21 mag 2026
News
New NGINX 0-Day RCE “nginx-poolslip” Affects Millions of NGINX Servers

New NGINX 0-Day RCE “nginx-poolslip” Affects Millions of NGINX Servers A newly disclosed zero-day remote code execution (RCE) vulnerability, dubbed nginx-poolslip, has been identified in NGINX version 1.31.0, the latest stable release of the widely deployed web server so ... Read more Published Date: May 21, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42945

CVEfeed Newsroom21 mag 2026
News
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a ca ... Read more Published Date: May 21, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-46333 CVE-2026-42897 CVE-2026-41940

CVEfeed Newsroom21 mag 2026
VulnerabilitàAlta
CVE-2026-7836 - hextoint macro uppercase bug

CVE ID :CVE-2026-7836 Published : May 21, 2026, 7:35 a.m. | 41 minutes ago Description :In Netatalk 2.0.0 through 4.4.2, hextoint macro uppercase bug. Fixed in 4.5.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-7835 - Format string argument mismatch

CVE ID :CVE-2026-7835 Published : May 21, 2026, 7:35 a.m. | 42 minutes ago Description :In Netatalk 3.0.3 through 4.4.2, format string argument mismatch. Fixed in 4.5.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026

Pagina 1516 di 2985

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.