Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36187 risultati

News
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the fami ... Read more Published Date: May 18, 2026 (2 days, 14 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom18 mag 2026
VulnerabilitàAlta
CVE-2026-42009 (CVSS 7.5)

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

NVD (NIST)18 mag 2026
VulnerabilitàAlta
CVE-2026-42009 - Gnutls: gnutls: denial of service via dtls packet reordering vulnerability

CVE ID :CVE-2026-42009 Published : May 18, 2026, 1:16 p.m. | 4 hours, 55 minutes ago Description :A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-8803 - opensourcepos Open Source Point of Sale Employee Login Employee.php login weak hash

CVE ID :CVE-2026-8803 Published : May 18, 2026, 12:16 p.m. | 5 hours, 56 minutes ago Description :A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitability is considered difficult. The actual existence of this vulnerability is currently in question. The vendor explains: "[T]he code is still there to allow the upgrade path to work. The default password is initially seeded with the old hash function, but then migrated to a newer one after login. [T]he hash version check might be cleaned up in the future. Currently it's not actively in use as any password change will use a newer hash function." Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-4320 - Authorization Bypass in ICMS Content Management by Creartia Internet Consulting

CVE ID :CVE-2026-4320 Published : May 18, 2026, 11:16 a.m. | 6 hours, 56 minutes ago Description :Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process, causing the script to continue running and enabling privilege escalation without the need for credentials. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-8802 - opensourcepos Open Source Point of Sale Items.php getPicThumb path traversal

CVE ID :CVE-2026-8802 Published : May 18, 2026, 11:16 a.m. | 6 hours, 56 minutes ago Description :A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identified as def0c27a0e252668df8d942fc31e16d1edfd7323. A patch should be applied to remediate this issue. The vendor was contacted early about this disclosure. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-41119 - Dell Live Optics Certificate Validation Vulnerability

CVE ID :CVE-2026-41119 Published : May 18, 2026, 11:16 a.m. | 4 hours, 56 minutes ago Description :Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-0983 - Denial of service vulnerability in M-Files Server

CVE ID :CVE-2026-0983 Published : May 18, 2026, 12:16 p.m. | 5 hours, 56 minutes ago Description :Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
News
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws

Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the l ... Read more Published Date: May 18, 2026 (2 days, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom18 mag 2026
VulnerabilitàAlta
CVE-2026-7304 - CVE-2026-7304

CVE ID :CVE-2026-7304 Published : May 18, 2026, 12:16 p.m. | 5 hours, 56 minutes ago Description :SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-7302 - CVE-2026-7302

CVE ID :CVE-2026-7302 Published : May 18, 2026, 12:16 p.m. | 5 hours, 56 minutes ago Description :SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-7301 - CVE-2026-7301

CVE ID :CVE-2026-7301 Published : May 18, 2026, 12:16 p.m. | 5 hours, 56 minutes ago Description :SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026

Pagina 1589 di 3016

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.