News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36255 risultati
CVE ID :CVE-2026-39054 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operating system command execution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-38728 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-14972 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerability. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-67437 Published : May 15, 2026, 3:16 p.m. | 50 minutes ago Description :Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows arbitrary user password reset. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20182 – Cisco Catalyst SD-WAN Auth Bypass to KEV OverviewCVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart), wh ... Read more Published Date: May 15, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20182 CVE-2026-20133 CVE-2026-20128 CVE-2026-20127 CVE-2026-20122
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively ... Read more Published Date: May 15, 2026 (3 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-44118 CVE-2026-44115 CVE-2026-44113 CVE-2026-44112 CVE-2026-23918
CVE ID :CVE-2026-41553 Published : May 15, 2026, 1:16 p.m. | 2 hours, 51 minutes ago Description :PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by Node.js and subsequently executed. This can lead to server compromise. This issue was fixed in PDF Export Module version 0.7.6. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7182 Published : May 15, 2026, 1:16 p.m. | 2 hours, 51 minutes ago Description :Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated pdf. This issue was fixed in version 1.1.1. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41552 Published : May 15, 2026, 1:16 p.m. | 2 hours, 51 minutes ago Description :PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version 0.7.6. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Living Off the Pipeline: Defending Against CI/CD Subversion The software supply chain has become one of the most attractive targets for modern adversaries, but the attacks seen in 2025 did not focus solely on poisoning dependencies or hijacking packages. Incre ... Read more Published Date: May 15, 2026 (3 days, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2023-42793
CVE ID :CVE-2026-46333 Published : May 15, 2026, 2:16 p.m. | 1 hour, 51 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don't have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses 'dumpable' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for threads that no longer have a VM (and maybe never did, like most kernel threads). It's not what this flag was designed for, but it is what it is. The ptrace code does check that the uid/gid matches, so you do have to be uid-0 to see kernel thread details, but this means that the traditional "drop capabilities" model doesn't make any difference for this all. Make it all make a *bit* more sense by saying that if you don't have a MM pointer, we'll use a cached "last dumpability" flag if the thread ever had a MM (it will be zero for kernel threads since it is never set), and require a proper CAP_SYS_PTRACE capability to override. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Kritiek Exim-lek maakt remote code execution op mailserver mogelijk Een kritieke kwetsbaarheid in Exim maakt op mailservers remote code execution door een ongeauthenticeerde aanvaller mogelijk. Er is een update verschenen waarmee het probleem (CVE-2026-45185) wordt ve ... Read more Published Date: May 15, 2026 (3 days, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45185
Pagina 1622 di 3022