Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36162 risultati

VulnerabilitàAlta
CVE-2026-44159 - Tyler Identity Local (TID-L) default administrative credentials

CVE ID :CVE-2026-44159 Published : May 19, 2026, 3:16 p.m. | 57 minutes ago Description :Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 2020, and has not been supported since 2021. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-43634 - HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header

CVE ID :CVE-2026-43634 Published : May 19, 2026, 3:16 p.m. | 57 minutes ago Description :HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's network. Attackers can exploit this to circumvent fail2ban brute-force protection, bypass per-user IP allowlists, and poison authentication audit logs by spoofing trusted IP addresses on each request. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-45557 - Technitium DNS Server excessive DNSSEC requests

CVE ID :CVE-2026-45557 Published : May 19, 2026, 3:16 p.m. | 57 minutes ago Description :Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network traffic. Fixed in 15.0. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-34883 - Dell Portrait Color Management Symbolic Link Escalation

CVE ID :CVE-2026-34883 Published : May 19, 2026, 3:16 p.m. | 57 minutes ago Description :An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate privileges to Administrator. During installation, the software writes the file CCFLFamily_07Feb11.edr to C:\ProgramData\Portrait Displays\CW\data\i1D3\ while running with elevated privileges. Because the installer does not properly validate symbolic links or reparse points at the destination path, an attacker can create a malicious link that redirects the write operation to an arbitrary system location, enabling arbitrary file creation or overwrite with elevated privileges. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-2587 - Glassfish Remote Code Execution Vulnerability

CVE ID :CVE-2026-2587 Published : May 19, 2026, 3:16 p.m. | 57 minutes ago Description :A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) “expressions” are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-2586 - GlassFish Administration Console Remote Code Execution Vulnerability

CVE ID :CVE-2026-2586 Published : May 19, 2026, 3:16 p.m. | 57 minutes ago Description :An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2025-51427 - ModelScope Code Execution Vulnerability

CVE ID :CVE-2025-51427 Published : May 19, 2026, 3:16 p.m. | 57 minutes ago Description :An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2025-70950 - Apache Go HTTP Directory Traversal Vulnerability

CVE ID :CVE-2025-70950 Published : May 19, 2026, 3:16 p.m. | 57 minutes ago Description :An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
News
Hackers Hijacking Four-Faith Industrial Routers for Botnet Activity

Hackers Hijacking Four-Faith Industrial Routers for Botnet Activity Hackers are actively exploiting Four-Faith industrial routers to build botnets, leveraging a critical vulnerability identified as CVE-2024-9643. Security researchers from CrowdSec report a sharp rise ... Read more Published Date: May 19, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-9643

CVEfeed Newsroom19 mag 2026
News
Critical Apache Flink Vulnerability Enables Remote code execution Attacks

Critical Apache Flink Vulnerability Enables Remote code execution Attacks A newly disclosed critical vulnerability in Apache Flink, tracked as CVE-2026-35194, exposes distributed data processing environments to remote code execution (RCE) attacks via SQL injection flaws in ... Read more Published Date: May 19, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-35194

CVEfeed Newsroom19 mag 2026
News
DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed DirtyDecrypt (aka Dirty ... Read more Published Date: May 19, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom19 mag 2026
VulnerabilitàAlta
CVE-2026-8706 - Sensitive user data could be leaked to other applications through Reader mode

CVE ID :CVE-2026-8706 Published : May 19, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026

Pagina 1572 di 3014

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.