Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35818 risultati

VulnerabilitàAlta
CVE-2025-32750 - Dell PowerFlex Manager Directory Listing Vulnerability

CVE ID :CVE-2025-32750 Published : May 20, 2026, 4:16 p.m. | 1 hour, 59 minutes ago Description :Dell PowerFlex Manager, version(s) Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-9084 - MISP OIDC authentication bypass via automatic email-based account linking under insecure IdP configurations

CVE ID :CVE-2026-9084 Published : May 20, 2026, 4:16 p.m. | 1 hour, 59 minutes ago Description :MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an attacker with a valid OIDC token could assert a victim’s email address and authenticate as that user, leading to account takeover. Severity: 6.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-24425 (CVSS 8.8)

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.

NVD (NIST)20 mag 2026
VulnerabilitàAlta
CVE-2026-22554 (CVSS 7.8)

MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability

NVD (NIST)20 mag 2026
VulnerabilitàAlta
CVE-2026-22554 - MediaArea MediaInfoLib Heap Overflow

CVE ID :CVE-2026-22554 Published : May 20, 2026, 2:16 p.m. | 1 hour, 59 minutes ago Description :MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-24425 - Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface

CVE ID :CVE-2026-24425 Published : May 20, 2026, 2:16 p.m. | 1 hour, 59 minutes ago Description :Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-8488 - Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation

CVE ID :CVE-2026-8488 Published : May 20, 2026, 4:16 p.m. | 1 hour, 59 minutes ago Description :Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2023-7346 - Ledger Bitcoin App 2.1.0 Address Derivation Error via Miniscript

CVE ID :CVE-2023-7346 Published : May 20, 2026, 2:13 p.m. | 2 hours, 2 minutes ago Description :Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that cause the device to derive and display incorrect receiving addresses, potentially leading to funds being sent to unintended addresses. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
News
FreePBX Vulnerability Allow Attackers to Gain Access to User Portals

FreePBX Vulnerability Allow Attackers to Gain Access to User Portals A critical vulnerability in the open-source IP PBX platform FreePBX could allow unauthenticated attackers to access user portals. The issue, tracked as CVE-2026-46376, affects the User Control Panel ( ... Read more Published Date: May 20, 2026 (1 day, 15 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom20 mag 2026
VulnerabilitàAlta
CVE-2026-8487 - Incorrect default permissions vulnerability in Progress Software MOVEit Automation

CVE ID :CVE-2026-8487 Published : May 20, 2026, 4:16 p.m. | 1 hour, 59 minutes ago Description :Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-8486 - Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation

CVE ID :CVE-2026-8486 Published : May 20, 2026, 4:16 p.m. | 1 hour, 59 minutes ago Description :Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-8485 - Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation

CVE ID :CVE-2026-8485 Published : May 20, 2026, 2:17 p.m. | 1 hour, 58 minutes ago Description :Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026

Pagina 1526 di 2985

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.