News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36515 risultati
Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026.
CVE ID :CVE-2026-41713 Published : May 12, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41712 Published : May 12, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-32684 Published : May 12, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information. Severity: 2.9 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-2465 Published : May 12, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Copy.Fail Linux Vulnerability This is the worst Linux vulnerability in years. TL;DR copy.fail is a Linux kernel local privilege escalation, not a browser or clipboard attack. Disclosed by Theori on 29 April 2026 with a working PoC ... Read more Published Date: May 12, 2026 (16 hours, 34 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431
Vulnerability in Code Runner MCP Server project Vulnerability in Code Runner MCP Server project CVE ID CVE-2026-5029 Publication date 12 May 2026 Vendor Code Runner MCP Server Product Code Runner MCP Server Vulnerable versions All Vulnerability typ ... Read more Published Date: May 12, 2026 (16 hours, 45 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-5029
CVE ID :CVE-2026-8162 Published : May 12, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :[email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter contains a malformed percent-encoding, the parser invokes decodeURI on the value without try/catch. The resulting URIError propagates as an uncaught exception and crashes the process. Impact: any service accepting multipart uploads via multiparty is affected. Workarounds: none. Upgrade to [email protected] or higher. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This issue affects BAPSİS: before v.202604152042.
CVE ID :CVE-2026-6001 Published : May 12, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This issue affects BAPSİS: before v.202604152042. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6813 Published : May 12, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6800 Published : May 12, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1711 di 3043