Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

VulnerabilitàAlta
CVE-2026-8115 - gyoridavid short-video-maker REST API rest.ts path traversal

CVE ID :CVE-2026-8115 Published : May 7, 2026, 11:16 p.m. | 3 hours, 9 minutes ago Description :A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts of the component REST API. The manipulation of the argument req.params.tmpFile results in path traversal. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-42880 - ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

CVE ID :CVE-2026-42880 Published : May 7, 2026, 11:16 p.m. | 3 hours, 9 minutes ago Description :Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-6411 - MAXHUB Pivot Client Application Use of a Broken or Risky Cryptographic Algorithm

CVE ID :CVE-2026-6411 Published : May 7, 2026, 11:16 p.m. | 3 hours, 9 minutes ago Description :This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain encrypted tenant email addresses and related metadata from any tenant. Due to the presence of a hardcoded AES key within the application, the encrypted data can be decrypted, enabling access to tenant email addresses and associated information in cleartext. Furthermore, an attacker may be able to cause a denial-of-service condition by enrolling multiple unauthorized devices into a tenant via MQTT, potentially disrupting tenant operations. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-2710 - CVE-2022-1234: Cisco Webex Meeting Server Authentication Bypass

CVE ID :CVE-2026-2710 Published : May 7, 2026, 11:16 p.m. | 3 hours, 9 minutes ago Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàCritica
CVE-2026-42826 (CVSS 10)

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-41105 (CVSS 8.1)

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-41105 - Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability

CVE ID :CVE-2026-41105 Published : May 7, 2026, 10:16 p.m. | 4 hours, 9 minutes ago Description :Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-40214 - OpenStack Cyborg Accelerator Request API Cross-Tenant Denial of Service

CVE ID :CVE-2026-40214 Published : May 7, 2026, 10:16 p.m. | 2 hours, 9 minutes ago Description :In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-42826 - Azure DevOps Information Disclosure Vulnerability

CVE ID :CVE-2026-42826 Published : May 7, 2026, 10:16 p.m. | 4 hours, 9 minutes ago Description :Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-35435 (CVSS 8.6)

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

NVD (NIST)07 mag 2026
VulnerabilitàCritica
CVE-2026-35428 (CVSS 9.6)

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-34327 (CVSS 8.2)

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.

NVD (NIST)07 mag 2026

Pagina 1790 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.