Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45042 risultati

VulnerabilitàAlta
CVE-2026-93545 - Out-of-bounds read in libXi's XListInputDevices()

CVE ID :CVE-2026-93545 Published : Sept. 24, 2026, 4:20 p.m. | 39 minutes ago Description :An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-94611 - authentik: Stored credentials are readable with view permission alone

CVE ID :CVE-2026-94611 Published : Sept. 24, 2026, 4:18 p.m. | 41 minutes ago Description :authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications using a client or shared secret, and applications using a proxy provider. Deployments are affected when view permission is granted to accounts that are not intended to read these credentials; deployments where every viewer is permitted to read them are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-97226 - DbGate files-style Endpoint files.js fs.readFile path traversal

CVE ID :CVE-2026-97226 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument filePath/uri leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-97225 - DbGate JSON Runner runners.js code injection

CVE ID :CVE-2026-97225 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing a manipulation of the argument comment.text/script.schedule can lead to code injection. The attack may be performed from remote. Upgrading to version 7.2.5-beta.6 mitigates this issue. This patch is called 70e7b6b58e464d7a015ba16e8d7574b420ee4877. Upgrading the affected component is advised. This issue is distinct from CVE-2026-47668. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-96873 - Reflected XSS in CirrusSearch debug explain output

CVE ID :CVE-2026-96873 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-96750 - Shell script injection via server-supplied database name in Open MongoDB shell

CVE ID :CVE-2026-96750 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-96744 - Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB integration for Laravel

CVE ID :CVE-2026-96744 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than as a literal value. An authenticated user who can influence the owner value an application uses when acquiring or restoring a lock may take over or prematurely expire a lock held by another process, which can lead to duplicated or conflicting operations. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-96746 - Heap buffer overflow via mid-scan command list growth in client topology monitoring

CVE ID :CVE-2026-96746 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-96745 - PHP object injection via unsuppressible __pclass class inference in command monitoring events

CVE ID :CVE-2026-96745 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database operation, an unauthenticated party who controls that data may cause an application class implementing the driver's persistable interface to be instantiated and its unserialization method invoked with the supplied data. The resulting impact depends on the classes available in the application. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-93541 - Out-of-bounds read in libXi's XQueryDeviceState()

CVE ID :CVE-2026-93541 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-93425 - Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root

CVE ID :CVE-2026-93425 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metacharacters into repoPath and execute arbitrary commands through child_process.exec as root in the Dokploy container. The supplied service identifier is used only to resolve the server and does not constrain repoPath. Because the standard deployment mounts /var/run/docker.sock, container-root command execution can be used to control Docker and compromise the host and its managed applications. This issue is fixed in version 0.29.13. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-93280 - greybus: audio: bound the topology section sizes against the fetched size

CVE ID :CVE-2026-93280 Published : Sept. 24, 2026, 4:17 p.m. | 42 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get_topology() fetches a topology blob of a module-supplied size, and gbaudio_tplg_parse_data() then walks it by adding the module-supplied size_dais, size_controls and size_widgets fields to form the control, widget and route section offsets. Those le32 sizes are never checked against the fetched blob, so a module reporting a small topology size but large section sizes makes the offsets point past the allocation, and parsing reads out of bounds. Reject a topology whose section sizes do not fit within the fetched size before it is parsed. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026

Pagina 152 di 3754

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.