Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

VulnerabilitàAlta
CVE-2026-42276 - Onyx: IDOR in /chat/stop-chat-session allows any authenticated user to interrupt other users chat sessions

CVE ID :CVE-2026-42276 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active chat session. The endpoint checks authentication but never verifies the session belongs to the caller. An attacker who knows a chat session UUID can kill another user's LLM generation mid-stream. This issue has been patched in versions 3.0.9, 3.1.6, and 3.2.6. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2023-42346 - Alkacon OpenCms XXE External Host Reference Vulnerability

CVE ID :CVE-2023-42346 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :Alkacon OpenCms before 16 allows XXE when the refers to an external host. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2023-42344 - Alkacon OpenCms XML External Entity (XXE) Information Disclosure

CVE ID :CVE-2023-42344 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2023-42345 - Alkacon OpenCms Cross Site Scripting (XSS)

CVE ID :CVE-2023-42345 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2022-26523 - Avast/AVG Windows Anti Rootkit Double Fetch Vulnerability

CVE ID :CVE-2022-26523 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2023-42343 - Alkacon OpenCms Cross Site Scripting Vulnerability

CVE ID :CVE-2023-42343 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2022-45899 - Nokia Broadcast Message Center (BMC) Root OS Command Injection Vulnerability

CVE ID :CVE-2022-45899 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2022-26522 - Avast AVG Windows Anti Rootkit Double Fetch Vulnerability

CVE ID :CVE-2022-26522 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2022-23961 - Thruk Monitoring Reflected Cross-Site Scripting

CVE ID :CVE-2022-23961 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
News
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions

Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as a successor to Copy Fail (CVE-2026-31 ... Read more Published Date: May 08, 2026 (3 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431 CVE-2026-33626 CVE-2026-32202 CVE-2026-3854 CVE-2022-27666

CVEfeed Newsroom08 mag 2026
VulnerabilitàAlta
CVE-2026-8133 (CVSS 7.3)

A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php of the component Shares Filelist API. Such manipulation of the argument order leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is e20ec58414103f781858f2951d178e19b1736664. A patch should be applied to remediate this issue.

NVD (NIST)08 mag 2026
VulnerabilitàAlta
CVE-2026-8133 - zyx0814 FilePress Shares Filelist API admin.php sql injection

CVE ID :CVE-2026-8133 Published : May 8, 2026, 4:16 a.m. | 2 hours, 9 minutes ago Description :A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php of the component Shares Filelist API. Such manipulation of the argument order leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is e20ec58414103f781858f2951d178e19b1736664. A patch should be applied to remediate this issue. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026

Pagina 1785 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.