Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36688 risultati

VulnerabilitàAlta
CVE-2026-8290 - Open5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of service

CVE ID :CVE-2026-8290 Published : May 11, 2026, 2:16 p.m. | 14 minutes ago Description :A security flaw has been discovered in Open5GS up to 2.7.7. This issue affects the function smf_nsmf_handle_update_data_in_vsmf of the file /src/smf/nsmf-handler.c of the component SMF. The manipulation results in denial of service. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2026-4802 (CVSS 8)

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

NVD (NIST)11 mag 2026
News
Veel QNAP NAS-systemen kwetsbaar voor Linux Dirty Frag-lek

Veel QNAP NAS-systemen kwetsbaar voor Linux Dirty Frag-lek Veel NAS-systemen van fabrikant QNAP zijn kwetsbaar voor het Linux Dirty Frag-lek. Een beveiligingsupdate is echter nog niet beschikbaar. Dirty Frag combineert twee verschillende kernel-kwetsbaarheden ... Read more Published Date: May 11, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-43500 CVE-2026-43284

CVEfeed Newsroom11 mag 2026
News
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More

⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More Rough Monday. Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should’ve died years ago — ... Read more Published Date: May 11, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom11 mag 2026
News
Honderden Ivanti-servers missen patch voor actief aangevallen beveiligingslek

Honderden Ivanti-servers missen patch voor actief aangevallen beveiligingslek Honderden Ivanti-servers missen een beveiligingsupdate voor een kwetsbaarheid waar aanvallers actief misbruik van maken. Dat meldt The Shadowserver Foundation op basis van eigen onderzoek. Ivanti waar ... Read more Published Date: May 11, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-6973

CVEfeed Newsroom11 mag 2026
VulnerabilitàAlta
CVE-2025-9973 - Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover

CVE ID :CVE-2025-9973 Published : May 11, 2026, 12:16 p.m. | 2 hours, 14 minutes ago Description :Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations. A malicious actor with privileges to configure adaptive authentication within one organization can leverage this functionality to execute authentication logic on other organizations and sub-organizations. This flaw allows bypassing authorization boundaries between organizations, leading to unauthorized access to critical operations and user accounts in other organizations. When adaptive authentication is enabled in a multi-organization deployment, a malicious actor with privileges to configure adaptive authentication in one organization could exploit this feature to perform critical operations in other organizations without authorization. This may result in privilege escalation, unauthorized access to resources, and potential account takeover across organizations. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2025-10470 - Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability

CVE ID :CVE-2025-10470 Published : May 11, 2026, 12:16 p.m. | 2 hours, 14 minutes ago Description :The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2026-8288 - Open5GS SMF gsm-handler.c denial of service

CVE ID :CVE-2026-8288 Published : May 11, 2026, 1:16 p.m. | 1 hour, 14 minutes ago Description :A vulnerability was determined in Open5GS up to 2.7.7. This affects the function gsm_handle_pdu_session_modification_qos_flow_descriptions of the file src/smf/gsm-handler.c of the component SMF. Executing a manipulation of the argument n1SmMsg can lead to denial of service. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
News
Vulnerabilities in ATutor software

Vulnerabilities in ATutor software Vulnerabilities in ATutor software CVE ID CVE-2026-6909 Publication date 11 May 2026 Vendor ATutor Product ATutor Vulnerable versions 2.2.4 Vulnerability type (CWE) Improper Neutralization of Input Du ... Read more Published Date: May 11, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom11 mag 2026
VulnerabilitàAlta
CVE-2026-6956 - Reflected XSS in ATutor

CVE ID :CVE-2026-6956 Published : May 11, 2026, 10:16 a.m. | 4 hours, 14 minutes ago Description :ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported. Maintainers of this project were notified early about this vulnerability, but did not respond with the details of the vulnerability or vulnerable version range. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2026-6909 - Reflected XSS in ATutor

CVE ID :CVE-2026-6909 Published : May 11, 2026, 10:16 a.m. | 4 hours, 14 minutes ago Description :ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported. Maintainers of this project were notified early about this vulnerability, but did not respond with the details of the vulnerability or vulnerable version range. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2026-40636 - Dell ECS Hard-Coded Credentials Disclosure

CVE ID :CVE-2026-40636 Published : May 11, 2026, 10:16 a.m. | 4 hours, 14 minutes ago Description :Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026

Pagina 1745 di 3058

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.