News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36255 risultati
Vulnerabilities in DHTMLX software Vulnerabilities in DHTMLX software CVE ID CVE-2026-7182 Publication date 15 May 2026 Vendor DHTMLX Product Diagram Vulnerable versions From 1.0.0 to 1.1.1 Vulnerability type (CWE) Improper Limitation ... Read more Published Date: May 15, 2026 (3 days, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-7182 CVE-2026-41553 CVE-2026-41552
PraisonAI Vulnerability Exploited Within Hours of Public Disclosure As artificial intelligence frameworks become central to enterprise operations, a critical flaw in a popular AI platform has exposed organizations to serious security risks from threat actors. Within h ... Read more Published Date: May 15, 2026 (3 days, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-44338
Amazon Redshift JDBC Driver Vulnerabilities Enables Remote Code Execution Attacks A critical vulnerability in the Amazon Redshift JDBC driver has put enterprise applications at severe risk of Remote Code Execution (RCE). Threat actors can exploit this newly disclosed flaw simply by ... Read more Published Date: May 15, 2026 (3 days, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-8178
Multiple cPanel Vulnerabilities Allows Access to Sensitive System Resources In a severe blow to web hosting environments worldwide, administrators are racing against the clock to patch a massive wave of security vulnerabilities affecting cPanel and WebHost Manager (WHM). Thre ... Read more Published Date: May 15, 2026 (3 days, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-43500 CVE-2026-29202 CVE-2026-29201 CVE-2026-43284 CVE-2026-40684
CVE ID :CVE-2026-8503 Published : May 15, 2026, 12:17 p.m. | 3 hours, 50 minutes ago Description :Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator returns a SHA-256 hash of the built-in rand() function, the epoch time, and the PID, that is hashed again. These are predictable, low-entropy sources. Predicable session ids could allow an attacker to gain access to systems. Note that version 1.3.19 has a fallback without warning to use insecure session generation method if the call to Crypt::URandom::urandom fails. However, this is unlikely as Crypt::URandom is a hardcoded requirement of the module. This issue is similar to CVE-2025-40931 for Apache::Session::Generate::MD5. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8454 Published : May 15, 2026, 12:17 p.m. | 3 hours, 50 minutes ago Description :Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the parallel skip-image branch at imgif.c:790-805 calls DGifGetLine(GifFile, GifRow, Width) with no such check. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerability in SzafirHost software Vulnerability in SzafirHost software CVE ID CVE-2026-44088 Publication date 15 May 2026 Vendor Krajowa Izba Rozliczeniowa Product SzafirHost Vulnerable versions All before 1.2.1 Vulnerability type (CW ... Read more Published Date: May 15, 2026 (3 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-44088
Fragnesia Linux Kernel Flaw Enables Root Privilege Escalation Security researchers have disclosed a newly identified local privilege escalation vulnerability in the Linux Kernel, dubbed “Fragnesia,” which belongs to the broader Dirty Frag family of flaws. The is ... Read more Published Date: May 15, 2026 (2 days, 23 hours ago) Vulnerabilities has been mentioned in this article.
Microsoft verwacht misbruik van kritiek zero-click beveiligingslek in Outlook Microsoft verwacht dat aanvallers misbruik gaan maken van een kritieke kwetsbaarheid in Outlook waardoor aanvallers door het versturen van een e-mail code op systemen kunnen uitvoeren. Het doelwit hoe ... Read more Published Date: May 15, 2026 (3 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-40361
CVE ID :CVE-2026-41970 Published : May 15, 2026, 10:16 a.m. | 5 hours, 51 minutes ago Description :Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41969 Published : May 15, 2026, 10:16 a.m. | 5 hours, 51 minutes ago Description :Permission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41968 Published : May 15, 2026, 10:16 a.m. | 3 hours, 50 minutes ago Description :Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1623 di 3022