Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36515 risultati

VulnerabilitàAlta
CVE-2026-2465 (CVSS 8.8)

Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026.

NVD (NIST)12 mag 2026
VulnerabilitàAlta
CVE-2026-41713 - Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor

CVE ID :CVE-2026-41713 Published : May 12, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-41712 - ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage

CVE ID :CVE-2026-41712 Published : May 12, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-32684 - Apache Directory Information Disclosure

CVE ID :CVE-2026-32684 Published : May 12, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information. Severity: 2.9 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-2465 - Improper Authorization in E-Kalite's Turboard FOR-S

CVE ID :CVE-2026-2465 Published : May 12, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
News
Copy.Fail Linux Vulnerability

Copy.Fail Linux Vulnerability This is the worst Linux vulnerability in years. TL;DR copy.fail is a Linux kernel local privilege escalation, not a browser or clipboard attack. Disclosed by Theori on 29 April 2026 with a working PoC ... Read more Published Date: May 12, 2026 (16 hours, 34 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431

CVEfeed Newsroom12 mag 2026
News
Vulnerability in Code Runner MCP Server project

Vulnerability in Code Runner MCP Server project Vulnerability in Code Runner MCP Server project CVE ID CVE-2026-5029 Publication date 12 May 2026 Vendor Code Runner MCP Server Product Code Runner MCP Server Vulnerable versions All Vulnerability typ ... Read more Published Date: May 12, 2026 (16 hours, 45 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-5029

CVEfeed Newsroom12 mag 2026
VulnerabilitàAlta
CVE-2026-8162 - multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing

CVE ID :CVE-2026-8162 Published : May 12, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :[email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter contains a malformed percent-encoding, the parser invokes decodeURI on the value without try/catch. The resulting URIError propagates as an uncaught exception and crashes the process. Impact: any service accepting multipart uploads via multiparty is affected. Workarounds: none. Upgrade to [email protected] or higher. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-6001 (CVSS 8.8)

Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This issue affects BAPSİS: before v.202604152042.

NVD (NIST)12 mag 2026
VulnerabilitàAlta
CVE-2026-6001 - IDOR in Abis Technology's BAPSİS

CVE ID :CVE-2026-6001 Published : May 12, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This issue affects BAPSİS: before v.202604152042. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-6813 - Continually <= 4.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'continually_embed_code' Parameter

CVE ID :CVE-2026-6813 Published : May 12, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026
VulnerabilitàAlta
CVE-2026-6800 - FastBots <= 1.0.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings

CVE ID :CVE-2026-6800 Published : May 12, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 mag 2026

Pagina 1711 di 3043

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.