Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35818 risultati

VulnerabilitàAlta
CVE-2026-20199 - Cisco ThousandEyes Virtual Appliance SSL Certificate Command Execution Vulnerability

CVE ID :CVE-2026-20199 Published : May 20, 2026, 5:16 p.m. | 59 minutes ago Description :A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-20223 - Cisco Secure Workload Unauthorized API Access Vulnerability

CVE ID :CVE-2026-20223 Published : May 20, 2026, 5:16 p.m. | 59 minutes ago Description :A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-20171 - Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability

CVE ID :CVE-2026-20171 Published : May 20, 2026, 5:16 p.m. | 59 minutes ago Description :A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If the update propagates to an affected device, it could cause the device to drop the BGP session and flap with the BGP peer that is forwarding this update, resulting in a DoS condition. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
News
Windows Zero-Days Trilogy: Chaotic Eclipse’s Unpatched Assault

Windows Zero-Days Trilogy: Chaotic Eclipse’s Unpatched Assault Background: Who Is Chaotic Eclipse?Security researcher Chaotic Eclipse, operating under the GitHub handle Nightmare-Eclipse, has published working exploit code for five separate Windows vulnerabilitie ... Read more Published Date: May 20, 2026 (1 day, 15 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33825 CVE-2020-17103

CVEfeed Newsroom20 mag 2026
VulnerabilitàAlta
CVE-2026-20238 - Improper Access Control through Role Inheritance in Splunk AI Toolkit app

CVE ID :CVE-2026-20238 Published : May 20, 2026, 4:32 p.m. | 1 hour, 43 minutes ago Description :In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the Splunk platform combines inherited search filters with the `OR` SPL operator, the injected filter overrides more restrictive filters on child roles. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-20240 - Denial of Service through coldToFrozen.sh Script in Splunk Enterprise

CVE ID :CVE-2026-20240 Published : May 20, 2026, 4:32 p.m. | 1 hour, 43 minutes ago Description :In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause a Denial of Service by exploiting the `coldToFrozen.sh` script in the `splunk_archiver` app to rename critical Splunk directories, making the instance non-functional.The Denial of Service is possible because of missing input validation in the `coldToFrozen.sh` script, which accepts arbitrary file paths and renames them without restricting operations to safe directories. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-5783 (CVSS 7.6)

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS. This issue affects CityPLus: before V24.29750.1.0.

NVD (NIST)20 mag 2026
VulnerabilitàAlta
CVE-2026-5783 - Reflected XSS in Beyaz Computer's CityPLus

CVE ID :CVE-2026-5783 Published : May 20, 2026, 4:16 p.m. | 1 hour, 59 minutes ago Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS. This issue affects CityPLus: before V24.29750.1.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-39047 - EPSON L14150 Buffer Overflow Remote Code Execution

CVE ID :CVE-2026-39047 Published : May 20, 2026, 4:16 p.m. | 1 hour, 59 minutes ago Description :Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100 Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-8598 - Unauthenticated Export Service in ZKTeco CCTV Cameras

CVE ID :CVE-2026-8598 Published : May 20, 2026, 4:16 p.m. | 1 hour, 59 minutes ago Description :An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
News
ZKTeco-beveiligingscamera's via kritiek lek volledig over te nemen

ZKTeco-beveiligingscamera's via kritiek lek volledig over te nemen Beveiligingscamera's van fabrikant ZKTeco bevatten een kritieke kwetsbaarheid waardoor de apparaten op afstand door een aanvaller volledig zijn over te nemen. ZKTeco roept klanten op om de beschikbaar ... Read more Published Date: May 20, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom20 mag 2026
VulnerabilitàAlta
CVE-2026-4293 - Kieback & Peter DDC Building Controllers Cross-site Scripting

CVE ID :CVE-2026-4293 Published : May 20, 2026, 4:16 p.m. | 1 hour, 59 minutes ago Description :The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026

Pagina 1525 di 2985

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.