News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36737 risultati
CVE ID :CVE-2026-8259 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8261 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8262 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /accounts/chart-save. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8257 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and may be used. The patch is named 1251efbc1ea471c1311d2726b2bbe061ff2a291c. It is suggested to install a patch to address this issue. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8256 Published : May 11, 2026, 2:16 a.m. | 6 hours, 14 minutes ago Description :A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. This vulnerability affects unknown code of the file /accounts/mr-save. Such manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Patch Now: Apache CloudStack Plugs Proxmox and KVM Exploits in New LTS Release The Apache CloudStack project has urgently rolled out Long Term Support (LTS) versions 4.20.3.0 and 4.22.0.1 to address a cluster of seven security vulnerabilities. Spanning from “Low” to “Important” ... Read more Published Date: Mai 11, 2026 (1 Tag, 7 Stunden ago) Vulnerabilities has been mentioned in this article.
Root Access at Risk: Perl Injection and Symlink Flaws Hit cPanel & WHM Web hosting administrators and infrastructure teams need to be on high alert. A recent security advisory has revealed a trio of vulnerabilities impacting the widely used cPanel & WHM and WP Squared pl ... Read more Published Date: May 11, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.
The Q1 2026 Exploit Surge: AI Discovers the Flaws, APTs Reap the Rewards The first quarter of 2026 has set a blistering and volatile pace for the cybersecurity industry, marked by a massive surge in vulnerability disclosures and highly sophisticated exploitation chains. Ac ... Read more Published Date: May 11, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.
Zero-Click Shell: Public Exploit and PoC Disclosed for Android’s Critical ADB Auth Bypass (CVE-2026-0073) A critical vulnerability existing within the core of Android’s developer tools has been exposed, revealing a zero-click avenue for attackers to silently hijack mobile devices over Wi-Fi. Detailed in a ... Read more Published Date: May 11, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.
Data Destruction and Memory Poisoning: Spring AI Vulnerabilities Threaten LLM Integrity Spring AI, a popular framework designed to simplify AI integration for Spring developers, has issued an security bulletin addressing three severe vulnerabilities. Ranging from data destruction to cros ... Read more Published Date: May 11, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-8253 Published : May 11, 2026, 12:16 a.m. | 4 hours, 13 minutes ago Description :A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8254 Published : May 11, 2026, 12:16 a.m. | 6 hours, 13 minutes ago Description :A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1753 di 3062