Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36187 risultati

VulnerabilitàAlta
CVE-2026-6341 - Incomplete group locking implementation

CVE ID :CVE-2026-6341 Published : 18. Mai 2026 08:16 | 3 Stunden, 55 Minuten ago Description :Mattermost Plugins versions Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-6342 - Group prefix matching bypass for subscriptions

CVE ID :CVE-2026-6342 Published : May 18, 2026, 8:16 a.m. | 5 hours, 55 minutes ago Description :Mattermost Plugins versions Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-3495 - Unescaped variables during error page composition

CVE ID :CVE-2026-3495 Published : May 18, 2026, 8:16 a.m. | 1 hour, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 3.8 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-4273 - Insufficient token rotation validation in remote cluster invite confirmation

CVE ID :CVE-2026-4273 Published : May 18, 2026, 8:16 a.m. | 1 hour, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-3637 - Mattermost fails to enforce create_post permission when editing posts

CVE ID :CVE-2026-3637 Published : May 18, 2026, 8:16 a.m. | 1 hour, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-2325 - Improper Input Validation in MS Teams Meetings API Handler

CVE ID :CVE-2026-2325 Published : May 18, 2026, 8:16 a.m. | 1 hour, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-28759 - Insufficient authorization in shared channel membership sync allows remote cluster to remove users from arbitrary channels

CVE ID :CVE-2026-28759 Published : May 18, 2026, 8:16 a.m. | 1 hour, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-8788 - Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections

CVE ID :CVE-2026-8788 Published : May 18, 2026, 8:16 a.m. | 5 hours, 55 minutes ago Description :Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note that version 0.9.0 fixed a similar issue CVE-2026-46719 for metric names. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-6334 - OAuth authorization code client binding not enforced during token redemption in Mattermost

CVE ID :CVE-2026-6334 Published : May 18, 2026, 8:16 a.m. | 1 hour, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
News
New Windows ‘MiniPlasma’ Zero-Day Let Attackers Gain SYSTEM Access – PoC Released

New Windows ‘MiniPlasma’ Zero-Day Let Attackers Gain SYSTEM Access – PoC Released A critical Windows privilege escalation zero-day vulnerability dubbed “MiniPlasma” has emerged with a public proof-of-concept exploit that allows attackers to achieve SYSTEM-level privileges on fully ... Read more Published Date: May 18, 2026 (2 days, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2020-17103

CVEfeed Newsroom18 mag 2026
News
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw ... Read more Published Date: May 18, 2026 (2 days, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897 CVE-2026-41940 CVE-2025-62221 CVE-2020-17103

CVEfeed Newsroom18 mag 2026
VulnerabilitàAlta
CVE-2026-8785 (CVSS 7.3)

A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Parameter Handler. Executing a manipulation of the argument appointment_no can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)18 mag 2026

Pagina 1592 di 3016

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.