News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36547 risultati
CVE ID :CVE-2026-34260 Published : May 12, 2026, 3:16 a.m. | 3 hours, 14 minutes ago Description :SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database without proper validation or sanitization. Upon successful exploitation, an attacker may gain unauthorized access to sensitive database information and could potentially crash the application. This vulnerability has a high impact on the confidentiality and availability of the application, while integrity remains unaffected. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40129 Published : May 12, 2026, 3:16 a.m. | 3 hours, 14 minutes ago Description :Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in execution. Successful exploitation could enable the attacker to execute arbitrary code for other users, resulting in a low impact on the integrity, with no impact to the confidentiality and availability of the system. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-34263 Published : May 12, 2026, 3:16 a.m. | 3 hours, 14 minutes ago Description :Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-0502 Published : May 12, 2026, 3:16 a.m. | 1 hour, 14 minutes ago Description :Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality of the data. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-45392 Published : May 12, 2026, 2:16 a.m. | 2 hours, 14 minutes ago Description :Reserved. Details will be published at disclosure. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-45393 Published : May 12, 2026, 2:16 a.m. | 2 hours, 14 minutes ago Description :Reserved. Details will be published at disclosure. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-45391 Published : May 12, 2026, 2:16 a.m. | 2 hours, 14 minutes ago Description :Reserved. Details will be published at disclosure. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical PrestaShop Flaw Allows Hijacking via “Contact Us” Form PrestaShop, the global open-source e-commerce powerhouse known for its highly customizable PHP architecture and responsive design, has issued an urgent security update. Used by merchants worldwide to ... Read more Published Date: May 12, 2026 (21 hours, 28 minutes ago) Vulnerabilities has been mentioned in this article.
Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets The software supply chain has just weathered another high-impact assault. The Socket Threat Research team has uncovered a significant compromise affecting 84 npm package artifacts within the popular t ... Read more Published Date: May 12, 2026 (22 hours, 3 minutes ago) Vulnerabilities has been mentioned in this article.
9.6 Severity: Critical “Cline” AI Agent Flaw Allows Stealthy RCE via Your Browser In the rapidly evolving world of AI-assisted development, tools like Cline have become indispensable, living in editors and terminals to help engineers build features through natural conversation. How ... Read more Published Date: May 12, 2026 (18 hours, 19 minutes ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-45362 Published : May 12, 2026, 1:16 a.m. | 3 hours, 14 minutes ago Description :Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file. Severity: 3.2 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-45321 Published : May 12, 2026, 1:16 a.m. | 3 hours, 14 minutes ago Description :On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1722 di 3046