Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36213 risultati

VulnerabilitàAlta
CVE-2026-8766 - Kilo-Org kilocode Environment Variable config.ts load information disclosure

CVE ID :CVE-2026-8766 Published : May 17, 2026, 11:17 p.m. | 6 hours, 54 minutes ago Description :A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2026-8767 - vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection

CVE ID :CVE-2026-8767 Published : May 17, 2026, 11:17 p.m. | 6 hours, 54 minutes ago Description :A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2026-8765 - Kilo-Org kilocode File Diff API Endpoint worktree-diff.ts Bun.file path traversal

CVE ID :CVE-2026-8765 Published : May 17, 2026, 11:17 p.m. | 6 hours, 54 minutes ago Description :A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff API Endpoint. Performing a manipulation of the argument File results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2026-8770 - continuedev continue JSON-RPC Server lsTool.ts lsTool path traversal

CVE ID :CVE-2026-8770 Published : May 18, 2026, 12:16 a.m. | 5 hours, 55 minutes ago Description :A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/tools/implementations/lsTool.ts of the component JSON-RPC Server. Such manipulation of the argument dirPath leads to path traversal. An attack has to be approached locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2026-8764 (CVSS 7.2)

A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)17 mag 2026
VulnerabilitàAlta
CVE-2026-8764 - H3C Magic B3 aspForm UpdateWanParams buffer overflow

CVE ID :CVE-2026-8764 Published : May 17, 2026, 10:16 p.m. | 7 hours, 55 minutes ago Description :A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2026-8721 - Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs

CVE ID :CVE-2026-8721 Published : May 17, 2026, 7:16 p.m. | 10 hours, 55 minutes ago Description :Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded. The C code (or OpenSSL internally) calls strlen() on the buffer. Any password byte at or after the first NULL is silently dropped. Binary / KDF-derived / HMAC-derived passwords lose entropy without any warnings. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2026-8507 - Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws

CVE ID :CVE-2026-8507 Published : May 17, 2026, 7:16 p.m. | 10 hours, 55 minutes ago Description :Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a signed integer overflow in the size calculation passed to Renew(). Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2026-46720 - Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections

CVE ID :CVE-2026-46720 Published : May 17, 2026, 6:16 p.m. | 11 hours, 55 minutes ago Description :Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2026-8759 (CVSS 7.3)

A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper neutralization of special elements used in an expression language statement. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)17 mag 2026
VulnerabilitàAlta
CVE-2026-8759 - xiandafu beetl SpELFunction SpELFunction.java expression language injection

CVE ID :CVE-2026-8759 Published : May 17, 2026, 3:16 p.m. | 10 hours, 55 minutes ago Description :A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper neutralization of special elements used in an expression language statement. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2026-8758 (CVSS 7.3)

A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)17 mag 2026

Pagina 1597 di 3018

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.