Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36249 risultati

VulnerabilitàAlta
CVE-2026-8669 - Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files

CVE ID :CVE-2026-8669 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-45736 - ws: Uninitialized memory disclosure

CVE ID :CVE-2026-45736 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-46483 - Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag

CVE ID :CVE-2026-46483 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479. Severity: 3.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-38728 - Nodemailer SMTP Denial of Service Vulnerability

CVE ID :CVE-2026-38728 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-39054 - Pamirs Oinone Command Injection Vulnerability

CVE ID :CVE-2026-39054 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operating system command execution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-39053 - Pamirs Oinone XXE File Disclosure/SSRF Vulnerability

CVE ID :CVE-2026-39053 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry points such as PamirsXmlUtils.fromXML(...) or ViewXmlUtils.fromXML(...), unsafe XML processing can lead to file disclosure or SSRF. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-39052 - Pamirs Oinone ScriptRunner Code Execution Vulnerability

CVE ID :CVE-2026-39052 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map context) evaluates attacker-controlled script expressions through the underlying script engine without sandboxing or allowlist restrictions. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-34253 - Vorbis-tools Ogg123 Buffer Underflow Vulnerability

CVE ID :CVE-2026-34253 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2025-14972 - Insufficient DPA countermeasure reseeding

CVE ID :CVE-2025-14972 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerability. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2025-67437 - MedicarePlus Password Reset Privilege Escalation

CVE ID :CVE-2025-67437 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows arbitrary user password reset. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
News
CVE-2026-20182 – Cisco Catalyst SD-WAN Auth Bypass to KEV

CVE-2026-20182 – Cisco Catalyst SD-WAN Auth Bypass to KEV OverviewCVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart), wh ... Read more Published Date: May 15, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20182 CVE-2026-20133 CVE-2026-20128 CVE-2026-20127 CVE-2026-20122

CVEfeed Newsroom15 mag 2026
News
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively ... Read more Published Date: May 15, 2026 (3 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-44118 CVE-2026-44115 CVE-2026-44113 CVE-2026-44112 CVE-2026-23918

CVEfeed Newsroom15 mag 2026

Pagina 1621 di 3021

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.