Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36321 risultati

VulnerabilitàAlta
CVE-2026-3160 - Unintended Proxy or Intermediary ('Confused Deputy') in GitLab

CVE ID :CVE-2026-3160 Published : May 14, 2026, 6:16 a.m. | 14 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project scope due to an integration filter functioning only as a display control rather than enforcing access boundaries as specified. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2026-3607 - Access Control Check Implemented After Asset is Accessed in GitLab

CVE ID :CVE-2026-3607 Published : May 14, 2026, 6:16 a.m. | 14 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass package protection rules due to improper access control. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2026-3829 - WP Encryption - One Click SSL & Force HTTPS <= 7.8.5.10 - Missing Authorization to Authenticated (Subscriber+) SSL Setup Tampering

CVE ID :CVE-2026-3829 Published : May 14, 2026, 6:16 a.m. | 14 minutes ago Description :The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'wple_basic_get_requests' function in all versions up to, and including, 7.8.5.10. This makes it possible for authenticated attackers, with subscriber level access and above, to reset the SSL setup state, force SSL to appear complete, and modify plan selection options. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2026-1322 - Business Logic Errors in GitLab

CVE ID :CVE-2026-1322 Published : May 14, 2026, 6:16 a.m. | 14 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in private projects due to improper authorization. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2026-1184 - Deserialization of Untrusted Data in GitLab

CVE ID :CVE-2026-1184 Published : May 14, 2026, 6:16 a.m. | 14 minutes ago Description :GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially crafted file due to improper validation. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2026-1338 - Authorization Bypass Through User-Controlled Key in GitLab

CVE ID :CVE-2026-1338 Published : May 14, 2026, 6:16 a.m. | 14 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to delete protected container registry tags due to improper authorization checks. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2026-1659 - Allocation of Resources Without Limits or Throttling in GitLab

CVE ID :CVE-2026-1659 Published : May 14, 2026, 6:16 a.m. | 14 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2026-2900 - Missing Authorization in GitLab

CVE ID :CVE-2026-2900 Published : May 14, 2026, 6:16 a.m. | 14 minutes ago Description :GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
News
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years. The vulnerability, disc ... Read more Published Date: May 14, 2026 (19 hours, 48 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-42946 CVE-2026-42945 CVE-2026-42934 CVE-2026-40701 CVE-2026-23918

CVEfeed Newsroom14 mag 2026
News
Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code

Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code A newly disclosed critical vulnerability in MongoDB could allow threat actors to execute arbitrary code, potentially handing them complete control over affected servers and exposing millions of record ... Read more Published Date: May 14, 2026 (17 hours, 53 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-8053

CVEfeed Newsroom14 mag 2026
News
The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access

The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access A ransomware group that only surfaced in mid-2025 has already made a significant mark on the threat landscape. The Gentlemen, a ransomware-as-a-service (RaaS) operation, has quickly risen to become on ... Read more Published Date: May 14, 2026 (18 hours, 2 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-33073 CVE-2025-32433 CVE-2024-55591

CVEfeed Newsroom14 mag 2026
VulnerabilitàAlta
CVE-2026-46446 - SOGo PostgreSQL/MariaDB SQL Injection

CVE ID :CVE-2026-46446 Published : May 14, 2026, 4:17 a.m. | 13 minutes ago Description :SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026

Pagina 1654 di 3027

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.