Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35841 risultati

VulnerabilitàAlta
CVE-2026-41470 - LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token

CVE ID :CVE-2026-41470 Published : May 19, 2026, 7:16 p.m. | 2 hours, 58 minutes ago Description :LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-33642 - Kitty has a Heap Buffer Over-Read/Write via Integer Overflow in compose_rectangles Bounds Check

CVE ID :CVE-2026-33642 Published : May 19, 2026, 7:16 p.m. | 57 minutes ago Description :Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Heap Buffer Over-Read/Write. An attacker who can write escape sequences to a kitty terminal (e.g., via a malicious file, SSH login banner, or piped content) can supply crafted x_offset/y_offset values that pass the bounds check after wrapping but cause massive out-of-bounds heap memory access in compose_rectangles(). No user interaction is required. No non-default configuration is required. The attacker only needs the ability to produce output in a kitty terminal window. This issue has been fixed in version 0.47.0. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-33637 - Faraday: Protocol-relative URI objects still bypass host scoping (possible incomplete fix for GHSA-33mh-2634-fwr2)

CVE ID :CVE-2026-33637 Published : May 19, 2026, 7:16 p.m. | 57 minutes ago Description :Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object (rather than a String) to Faraday::Connection#build_exclusive_url. This bypasses the February 2026 fix for GHSA-33mh-2634-fwr2 and enables off-host request forgery: a request built from a fixed-base Faraday::Connection can be redirected to an attacker-controlled host, forwarding connection-scoped values such as Authorization headers and default query parameters. This issue has been fixed in version 2.14.3. Severity: 0.0 | NONE Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-33741 - EspoCRM: Stored XSS via SVG attachment loading same-origin JavaScript

CVE ID :CVE-2026-33741 Published : May 19, 2026, 7:16 p.m. | 57 minutes ago Description :EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later serve those SVG files as top-level inline documents through both the attachment and image entry points, resulting in stored cross-user XSS reachable through a normal attachment workflow. Although inline SVG script is blocked by the response CSP, the same CSP still allows same-origin external script. As a result, an attacker can upload a malicious SVG together with a second attacker-controlled JavaScript attachment, then trick another user into opening the SVG to execute JavaScript in the victim's EspoCRM origin. This issue has been fixed in version 9.3.4. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-34154 - Discourse has a subscription access bypass in its discourse-subscriptions plugin

CVE ID :CVE-2026-34154 Published : May 19, 2026, 7:16 p.m. | 57 minutes ago Description :Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain access to subscription-gated groups without completing payment. This issue has been fixed in versions 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1. Severity: 2.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-32738 - libheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunk

CVE ID :CVE-2026-32738 Published : May 19, 2026, 7:16 p.m. | 57 minutes ago Description :libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an empty chunk and resulting in a denial of service. When any sample is accessed, the library reads from index 0 of an empty std::vector, causing a guaranteed SEGV (null-page read). The file parses successfully without producing an error; the crash occurs on the first frame access. This issue has been fixed in version 1.22.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-32739 - libheif is Vulnerable to Infinite Loop DoS via stts Sample Duration Lookup

CVE ID :CVE-2026-32739 Published : May 19, 2026, 8:16 p.m. | 1 hour, 58 minutes ago Description :libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2025-61081 - BYD Atto3 Authentication Key Disclosure

CVE ID :CVE-2025-61081 Published : May 19, 2026, 6:16 p.m. | 1 hour, 58 minutes ago Description :In BYD Atto3, an attacker can obtain an authentication key through Brute Force attack, which is permanently available. The authentication key enables flash to the Electronic Parking Break (EPB) and Supplemental Restoration System (SRS) related ECUs. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-33633 - Kitty has a Heap Buffer Overflow in its Graphics Protocol Handler

CVE ID :CVE-2026-33633 Published : May 19, 2026, 6:16 p.m. | 1 hour, 58 minutes ago Description :Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twice the initial buffer capacity. The overflow is attacker-controlled in both length and content, causing DoS and potentially escalation to RCE itself. This issue has been fixed in version 0.47.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-6009 - Jaspersoft Library Deserialisation Vulnerability

CVE ID :CVE-2026-6009 Published : May 19, 2026, 6:16 p.m. | 1 hour, 58 minutes ago Description :Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-32134 - NanoMQ: NULL Pointer Dereference Crash in tcptran_pipe_peer During Session Restore

CVE ID :CVE-2026-32134 Published : May 19, 2026, 6:16 p.m. | 1 hour, 58 minutes ago Description :NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the broker can crash due to a NULL pointer dereference during MQTT session resumption for clean_start=0 clients. The transport's p_peer callback (tcptran_pipe_peer()) iterates cpipe->subinfol while copying session metadata from the cached old pipe to the new reconnecting pipe, without checking whether the pointer is NULL. Under a reconnect race, cpipe->subinfol can be freed and set to NULL before session restore invokes this function, resulting in a remote unauthenticated Denial-of-Service (process crash) condition. This issue has been fixed in version 0.24.11. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
News
DirtyDecrypt Linux Kernel Vulnerability PoC Exploit Code Released

DirtyDecrypt Linux Kernel Vulnerability PoC Exploit Code Released A working proof-of-concept (PoC) exploit for a high-severity Linux kernel local privilege escalation vulnerability dubbed DirtyDecrypt, also tracked as DirtyCBC, enables local attackers to gain full r ... Read more Published Date: May 19, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-31635

CVEfeed Newsroom19 mag 2026

Pagina 1542 di 2987

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.