News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36342 risultati
CVE ID :CVE-2026-46419 Published : May 14, 2026, 2:17 a.m. | 2 hours, 13 minutes ago Description :Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
200K Sites at Risk: 9.8 CVSS RCE via Burst Statistics Auth Bypass Exploited in the Wild In a major discovery for the WordPress ecosystem, PRISM, Wordfence Threat Intelligence’s autonomous vulnerability research platform, has identified a critical authentication bypass vulnerability in Bu ... Read more Published Date: May 14, 2026 (21 hours, 46 minutes ago) Vulnerabilities has been mentioned in this article.
Architectural Breach: AMD Zen 2 Flaw Allows Higher-Privilege Instruction Corruption In a significant revelation for the hardware security world, AMD has identified a vulnerability targeting its Zen 2-based architecture. The flaw, tracked as CVE-2025-54518, resides deep within the pro ... Read more Published Date: May 14, 2026 (21 hours, 47 minutes ago) Vulnerabilities has been mentioned in this article.
GitLab Critical Patch: High-Severity XSS and Unauthenticated DoS Flaws Hit Self-Managed Instances In a major move to secure its DevOps platform, GitLab has released important security versions for both Community Edition (CE) and Enterprise Edition (EE). The updates—18.11.3, 18.10.6, and 18.9.7—add ... Read more Published Date: May 14, 2026 (18 hours, 6 minutes ago) Vulnerabilities has been mentioned in this article.
Critical 9.6 Severity Ivanti Xtraction Flaw Exposes Sensitive Data Ivanti has issued an urgent security update for its Xtraction platform to address a critical vulnerability. Carrying a CVSS score of 9.6, this flaw opens the door to severe data exposure and malicious ... Read more Published Date: May 14, 2026 (16 hours, 8 minutes ago) Vulnerabilities has been mentioned in this article.
Critical MongoDB Flaw CVE-2026-8053 Paves the Way for Server Takeover Time-series data is the backbone of countless modern applications, from financial tickers to IoT monitoring. However, a newly disclosed vulnerability in MongoDB Server is turning this powerful feature ... Read more Published Date: May 14, 2026 (16 hours, 35 minutes ago) Vulnerabilities has been mentioned in this article.
OPNsense Critical Root RCE (CVE-2026-44194 & CVE-2026-45158) Details and PoC Disclosed The open-source firewall community is on high alert today after critical security vulnerabilities in OPNsense were dragged into the light. The full technical details and proof-of-concept (PoC) exploit ... Read more Published Date: May 14, 2026 (14 hours, 50 minutes ago) Vulnerabilities has been mentioned in this article.
Microsoft MDASH: When the Machine Becomes the Red Team AI-native vulnerability discovery has crossed from research curiosity into production-grade defense — and the implications for how enterprises think about security engineering are irreversible.The Ann ... Read more Published Date: May 14, 2026 (12 hours, 57 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33827 CVE-2026-33824
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793) In a critical security alert for the PHP community, Nils Adermann, Co-Creator of Composer, has issued an urgent advisory regarding a vulnerability that inadvertently leaks sensitive GitHub authenticat ... Read more Published Date: May 14, 2026 (13 hours, 11 minutes ago) Vulnerabilities has been mentioned in this article.
Critical 18-Year-Old NGINX RCE (CVE-2026-42945) and GitHub PoC Disclosed Security researcher Zhenpeng (Leo) Lin of depthfirst has unveiled a critical, 18-year-old vulnerability lurking within NGINX. The flaw, tracked as CVE-2026-42945 (CVSS 9.2), is a deterministic heap bu ... Read more Published Date: May 14, 2026 (13 hours, 25 minutes ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-41281 Published : May 14, 2026, 12:16 a.m. | 4 hours, 14 minutes ago Description :Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify communications transmitted in plaintext, potentially resulting in information disclosure or data tampering. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8500 Published : May 13, 2026, 11:16 p.m. | 5 hours, 14 minutes ago Description :Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1657 di 3029