Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36515 risultati

VulnerabilitàAlta
CVE-2026-30810 - Server-Side Request Forgery in API Checker leads to Privilege Escalation

CVE ID :CVE-2026-30810 Published : May 12, 2026, 4:16 p.m. | 14 minutes ago Description :Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800 Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-31216 - Nexenta MinIO Unauthorized File Deletion Vulnerability

CVE ID :CVE-2026-31216 Published : May 12, 2026, 4:16 p.m. | 14 minutes ago Description :The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentication, authorization, and input validation mechanisms. Unauthenticated remote attackers can send crafted requests with a user-controlled object_name path parameter to delete arbitrary files from the underlying MinIO storage system. Successful exploitation leads to data loss and denial of service. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-30807 - Cross-Site Request Forgery on Extension Pages

CVE ID :CVE-2026-30807 Published : May 12, 2026, 4:16 p.m. | 14 minutes ago Description :Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800 Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-30808 - Session Fixation in Authentication leads to Session Hijacking

CVE ID :CVE-2026-30808 Published : May 12, 2026, 4:16 p.m. | 14 minutes ago Description :Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800 Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
News
Zoom Rooms and Workplace Vulnerabilities Allow Attackers to Escalate Privileges

Zoom Rooms and Workplace Vulnerabilities Allow Attackers to Escalate Privileges A series of newly discovered vulnerabilities in Zoom’s software ecosystem could hand local attackers the keys to your system. As organizations continue to rely heavily on virtual meetings, threat acto ... Read more Published Date: May 12, 2026 (21 hours, 59 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom12 mag 2026
News
SAP Patches Critical SQL injection Vulnerability in SAP S/4HANA

SAP Patches Critical SQL injection Vulnerability in SAP S/4HANA On May 12, 2026, SAP released its highly anticipated monthly Security Patch Day updates, addressing numerous severe security flaws across its entire enterprise software portfolio. The most alarming di ... Read more Published Date: May 12, 2026 (20 hours, 6 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-40137 CVE-2026-40136 CVE-2026-40135 CVE-2026-40134 CVE-2026-40133 CVE-2026-40132 CVE-2026-40131 CVE-2026-40129 CVE-2026-34263 CVE-2026-34260 CVE-2026-34259 CVE-2026-34258 CVE-2026-27682 CVE-2026-0502 CVE-2025-68161

CVEfeed Newsroom12 mag 2026
VulnerabilitàAlta
CVE-2026-8391 - Other issue in the JavaScript Engine component

CVE ID :CVE-2026-8391 Published : May 12, 2026, 2:17 p.m. | 13 minutes ago Description :Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-8390 - Use-after-free in the JavaScript: WebAssembly component

CVE ID :CVE-2026-8390 Published : May 12, 2026, 2:17 p.m. | 13 minutes ago Description :Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-8388 - Incorrect boundary conditions in the JavaScript Engine: JIT component

CVE ID :CVE-2026-8388 Published : May 12, 2026, 2:17 p.m. | 13 minutes ago Description :Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-8389 - JIT miscompilation in the JavaScript Engine: JIT component

CVE ID :CVE-2026-8389 Published : May 12, 2026, 2:17 p.m. | 13 minutes ago Description :JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-6865 - Improper Limitation of a Pathname to a Restricted Directory Vulnerability on Multiple Products

CVE ID :CVE-2026-6865 Published : May 12, 2026, 2:17 p.m. | 13 minutes ago Description :CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause unauthorized access to sensitive files when user-supplied input is improperly handled during server-side file path processing. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-45091 - sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)

CVE ID :CVE-2026-45091 Published : May 12, 2026, 2:17 p.m. | 13 minutes ago Description :sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dumps, kubectl describe pod, Sentry/Rollbar stack traces, log aggregators) could decode the payload and extract the TOTP secret in plaintext. This vulnerability is fixed in 0.1.0-alpha.4. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026

Pagina 1708 di 3043

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.