Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36737 risultati

VulnerabilitàAlta
CVE-2026-8241 - Industrial Application Software IAS Canias ERP RMI iasGetServerInfoEvent improper authorization

CVE ID :CVE-2026-8241 Published : May 10, 2026, 9:16 a.m. | 3 hours, 13 minutes ago Description :A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of the component RMI Interface. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-8234 (CVSS 8.8)

A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security_5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)10 mag 2026
VulnerabilitàAlta
CVE-2026-8234 - EFM ipTIME A8004T WifiBasicSet formWifiBasicSet stack-based overflow

CVE ID :CVE-2026-8234 Published : May 10, 2026, 7:16 a.m. | 5 hours, 13 minutes ago Description :A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security_5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-8235 - 8421bit MiniClaw System kernel.ts resolveSkillScriptPath os command injection

CVE ID :CVE-2026-8235 Published : May 10, 2026, 7:16 a.m. | 5 hours, 13 minutes ago Description :A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the component System Command Handler. The manipulation results in os command injection. The exploit is now public and may be used. The patch is identified as 223c16a1088e138838dcbd18cd65a37c35ac5a84. It is best practice to apply a patch to resolve this issue. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-45186 - Apache libexpat XML Denial of Service

CVE ID :CVE-2026-45186 Published : May 10, 2026, 7:16 a.m. | 5 hours, 13 minutes ago Description :In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. Severity: 2.9 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-8233 - Dotouch XproUPF access control

CVE ID :CVE-2026-8233 Published : May 10, 2026, 6:16 a.m. | 6 hours, 13 minutes ago Description :A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The vendor was contacted early about this disclosure. Severity: 4.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
News
New cPanel and WHM Flaws Enable Code Execution, DoS Attacks

New cPanel and WHM Flaws Enable Code Execution, DoS Attacks cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP S ... Read more Published Date: May 10, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-29203 CVE-2026-29202 CVE-2026-29201 CVE-2026-41940

CVEfeed Newsroom10 mag 2026
VulnerabilitàAlta
CVE-2026-8228 - Wavlink NU516U1 wireless.cgi advance os command injection

CVE ID :CVE-2026-8228 Published : May 10, 2026, 5:16 a.m. | 7 hours, 13 minutes ago Description :A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-8227 - Wavlink NU516U1 adm.cgi wzdapMesh os command injection

CVE ID :CVE-2026-8227 Published : May 10, 2026, 5:16 a.m. | 7 hours, 13 minutes ago Description :A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-8226 - Open5GS types.c ogs_pcc_rule_install_flow_from_media denial of service

CVE ID :CVE-2026-8226 Published : May 10, 2026, 5:16 a.m. | 7 hours, 13 minutes ago Description :A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-8225 - Open5GS delete Endpoint sm-sm.c pcf_npcf_smpolicycontrol_handle_delete denial of service

CVE ID :CVE-2026-8225 Published : May 10, 2026, 5:16 a.m. | 7 hours, 13 minutes ago Description :A vulnerability was identified in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-8229 - Wavlink NU516U1 wireless.cgi WifiBasic os command injection

CVE ID :CVE-2026-8229 Published : May 10, 2026, 5:16 a.m. | 7 hours, 13 minutes ago Description :A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypType results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026

Pagina 1759 di 3062

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.