Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36235 risultati

News
Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices

Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices A newly disclosed zero-click exploit chain targeting Google Pixel 10 devices has raised fresh concerns about Android’s low-level security. Google Project Zero researchers demonstrated how attackers co ... Read more Published Date: May 16, 2026 (3 days, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-54957

CVEfeed Newsroom16 mag 2026
VulnerabilitàAlta
CVE-2026-8681 - Essential Chat Support <= 1.0.1 - Missing Authorization to Unauthenticated Settings Reset via 'ecs_reset_settings' Parameter

CVE ID :CVE-2026-8681 Published : May 16, 2026, 3:16 a.m. | 10 hours, 53 minutes ago Description :The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to reset all plugin configuration settings — including general settings, display rules, custom CSS, and WooCommerce tab settings — to their defaults by sending a POST request with ecs_reset_settings=1. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
News
Fortinet Patch Tuesday – May 2026

Fortinet Patch Tuesday – May 2026 OverviewFortinet published 11 advisories on Patch Tuesday describing as many bugs, including two dealing with critical-severity code execution security defects. While the company did not tag these two ... Read more Published Date: May 16, 2026 (3 days, 14 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897 CVE-2026-44279 CVE-2026-44278 CVE-2026-44277 CVE-2026-26083 CVE-2026-25690 CVE-2026-25088 CVE-2025-67604 CVE-2025-53870 CVE-2025-53844 CVE-2025-53681 CVE-2025-53680 CVE-2026-22828 CVE-2026-35616 CVE-2026-21643

CVEfeed Newsroom16 mag 2026
News
CVSS 10 Alert: Quest KACE SMA Auth Bypass Exploited to Hijack Managed Endpoints

CVSS 10 Alert: Quest KACE SMA Auth Bypass Exploited to Hijack Managed Endpoints Detailed listing of tools and scripts within the exposed C2 directory | Image: Hunt Cybersecurity researchers have just dropped a report on a critical “management plane” threat that has spent the last ... Read more Published Date: May 16, 2026 (3 days, 14 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-44551 CVE-2026-46364 CVE-2026-45010 CVE-2021-47965 CVE-2026-44717 CVE-2026-41258 CVE-2026-8398 CVE-2026-5229 CVE-2026-44212 CVE-2026-8580 CVE-2026-42897 CVE-2026-20182 CVE-2026-8181 CVE-2026-42062 CVE-2026-32661 CVE-2026-6973 CVE-2026-41940 CVE-2026-1603 CVE-2025-32975

CVEfeed Newsroom16 mag 2026
VulnerabilitàAlta
CVE-2026-8704 - Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified

CVE ID :CVE-2026-8704 Published : May 15, 2026, 11:16 p.m. | 14 hours, 53 minutes ago Description :Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-8700 - Crypt::DSA versions before 1.20 for Perl generate seeds using rand

CVE ID :CVE-2026-8700 Published : May 15, 2026, 10:16 p.m. | 15 hours, 53 minutes ago Description :Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-45666 - Open WebUI: Indirect Object Reference (IDOR) in user notes

CVE ID :CVE-2026-45666 Published : May 15, 2026, 10:16 p.m. | 15 hours, 53 minutes ago Description :Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowing authenticated users to retrieve notes belonging to other users by guessing or enumerating UUIDs. This results in unauthorized disclosure of potentially sensitive or private user data. This vulnerability is fixed in 0.8.11. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-45346 - Open WebUI: Stored Cross-Site Scripting in SVG Renderer

CVE ID :CVE-2026-45346 Published : May 15, 2026, 10:16 p.m. | 15 hours, 53 minutes ago Description :Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.31, there is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation. This vulnerability is fixed in 0.6.31. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-45365 - Open WebUI: Authenticated users can bypass model access control via exposed query parameter

CVE ID :CVE-2026-45365 Published : May 15, 2026, 10:16 p.m. | 15 hours, 53 minutes ago Description :Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted models. This vulnerability is fixed in 0.8.11. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-45347 - Open WebUI: Blind server side request forgery (SSRF) via the PDF generate function

CVE ID :CVE-2026-45347 Published : May 15, 2026, 10:16 p.m. | 15 hours, 53 minutes ago Description :Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.11, there is a blind server side request forgery (SSRF) via the PDF generate function. In the PDF export, user inputs are interpreted as HTML and embedded into the PDF. According to tests, scripts and some potentially dangerous tags (iFrame, Object, etc.) are blocked, preventing server-side content from being read through this vulnerability. However, an image tag can be used to force a server-side request (SSRF), as shown in the following below. This vulnerability is fixed in 0.5.11. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-45351 - Open WebUI: Exposure of System Prompt to Regular User [Non-Admin]

CVE ID :CVE-2026-45351 Published : May 15, 2026, 10:16 p.m. | 15 hours, 53 minutes ago Description :Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.9, when a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application. This vulnerability is fixed in 0.8.9. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-44567 - Open WebUI: Open WebUI Improper Authorization Control

CVE ID :CVE-2026-44567 Published : May 15, 2026, 10:16 p.m. | 5 hours, 52 minutes ago Description :Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly validate that the user has an authorized user role of user. By default, when Open WebUI is configured with new sign-ups enabled, the default user role is set to pending. In this configuration, an administrator is required to go into the Admin management panel following a new user registration and reconfigure the user to have a role of either user or admin before that user is able to access the web application. This vulnerability is fixed in 0.1.124. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026

Pagina 1611 di 3020

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.