Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36713 risultati

VulnerabilitàAlta
CVE-2026-8257 - WebAssembly Binaryen BrOn wasm-ir-builder.cpp makeBrOn assertion

CVE ID :CVE-2026-8257 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and may be used. The patch is named 1251efbc1ea471c1311d2726b2bbe061ff2a291c. It is suggested to install a patch to address this issue. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2026-8258 - Squirrel sqstdstring.cpp validate_format stack-based overflow

CVE ID :CVE-2026-8258 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The attack can only be executed locally. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2026-8261 - Squirrel sqobject.cpp Load heap-based overflow

CVE ID :CVE-2026-8261 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2026-8259 - Tenda AC6 httpd telnet os command injection

CVE ID :CVE-2026-8259 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2026-8256 - Devs Palace ERP Online mr-save cross site scripting

CVE ID :CVE-2026-8256 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. This vulnerability affects unknown code of the file /accounts/mr-save. Such manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
News
Patch Now: Apache CloudStack Plugs Proxmox and KVM Exploits in New LTS Release

Patch Now: Apache CloudStack Plugs Proxmox and KVM Exploits in New LTS Release The Apache CloudStack project has urgently rolled out Long Term Support (LTS) versions 4.20.3.0 and 4.22.0.1 to address a cluster of seven security vulnerabilities. Spanning from “Low” to “Important” ... Read more Published Date: Mai 11, 2026 (1 Tag, 7 Stunden ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom11 mag 2026
News
Root Access at Risk: Perl Injection and Symlink Flaws Hit cPanel & WHM

Root Access at Risk: Perl Injection and Symlink Flaws Hit cPanel & WHM Web hosting administrators and infrastructure teams need to be on high alert. A recent security advisory has revealed a trio of vulnerabilities impacting the widely used cPanel & WHM and WP Squared pl ... Read more Published Date: May 11, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom11 mag 2026
News
The Q1 2026 Exploit Surge: AI Discovers the Flaws, APTs Reap the Rewards

The Q1 2026 Exploit Surge: AI Discovers the Flaws, APTs Reap the Rewards The first quarter of 2026 has set a blistering and volatile pace for the cybersecurity industry, marked by a massive surge in vulnerability disclosures and highly sophisticated exploitation chains. Ac ... Read more Published Date: May 11, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom11 mag 2026
News
Zero-Click Shell: Public Exploit and PoC Disclosed for Android’s Critical ADB Auth Bypass (CVE-2026-0073)

Zero-Click Shell: Public Exploit and PoC Disclosed for Android’s Critical ADB Auth Bypass (CVE-2026-0073) A critical vulnerability existing within the core of Android’s developer tools has been exposed, revealing a zero-click avenue for attackers to silently hijack mobile devices over Wi-Fi. Detailed in a ... Read more Published Date: May 11, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom11 mag 2026
News
Data Destruction and Memory Poisoning: Spring AI Vulnerabilities Threaten LLM Integrity

Data Destruction and Memory Poisoning: Spring AI Vulnerabilities Threaten LLM Integrity Spring AI, a popular framework designed to simplify AI integration for Spring developers, has issued an security bulletin addressing three severe vulnerabilities. Ranging from data destruction to cros ... Read more Published Date: May 11, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom11 mag 2026
VulnerabilitàAlta
CVE-2026-8255 - Devs Palace ERP Online add_new_customer cross site scripting

CVE ID :CVE-2026-8255 Published : May 11, 2026, 12:16 a.m. | 6 hours, 13 minutes ago Description :A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026
VulnerabilitàAlta
CVE-2026-8254 - Devs Palace ERP Online sales_save cross site scripting

CVE ID :CVE-2026-8254 Published : May 11, 2026, 12:16 a.m. | 6 hours, 13 minutes ago Description :A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11 mag 2026

Pagina 1751 di 3060

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.