Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33708 risultati

VulnerabilitàAlta
CVE-2026-71949 - D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup

CVE ID :CVE-2026-71949 Published : Aug. 8, 2026, 5:16 p.m. | 9 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàCritica
CVE-2026-71947 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71946 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71945 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71944 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàAlta
CVE-2026-71946 - D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun

CVE ID :CVE-2026-71946 Published : Aug. 8, 2026, 5:16 p.m. | 5 hours, 9 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71947 - D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun

CVE ID :CVE-2026-71947 Published : Aug. 8, 2026, 5:16 p.m. | 5 hours, 9 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71945 - D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom

CVE ID :CVE-2026-71945 Published : Aug. 8, 2026, 5:16 p.m. | 5 hours, 9 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71944 - D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel

CVE ID :CVE-2026-71944 Published : Aug. 8, 2026, 5:16 p.m. | 5 hours, 9 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-67620 (CVSS 7.7)

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services. Attackers can send requests to the fetch-links API endpoint with a crafted URL parameter, bypassing deny-list validation including redirect-based bypasses, to reach instance metadata services and expose instance identity data and role credentials on Oracle Cloud Infrastructure or Alibaba Cloud deployments, with unauthenticated access possible when URL-fetching nodes exist in public chatflows.

NVD (NIST)08 ago 2026
VulnerabilitàAlta
CVE-2026-42170 (CVSS 7.8)

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corruption and potential code execution.

NVD (NIST)08 ago 2026
VulnerabilitàAlta
CVE-2026-67620 - Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List

CVE ID :CVE-2026-67620 Published : Aug. 8, 2026, 4:16 p.m. | 6 hours, 9 minutes ago Description :Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services. Attackers can send requests to the fetch-links API endpoint with a crafted URL parameter, bypassing deny-list validation including redirect-based bypasses, to reach instance metadata services and expose instance identity data and role credentials on Oracle Cloud Infrastructure or Alibaba Cloud deployments, with unauthenticated access possible when URL-fetching nodes exist in public chatflows. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026

Pagina 153 di 2809

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.