News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36763 risultati
CVE ID :CVE-2026-7413 Published : May 7, 2026, 5:15 p.m. | 1 hour, 9 minutes ago Description :A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7415 Published : May 7, 2026, 5:15 p.m. | 1 hour, 9 minutes ago Description :The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7414 Published : May 7, 2026, 5:15 p.m. | 1 hour, 9 minutes ago Description :Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks Ivanti has issued a critical security advisory for its Endpoint Manager Mobile (EPMM) product, disclosing multiple actively exploited vulnerabilities, including CVE-2026-6973, and urging all on-premis ... Read more Published Date: May 07, 2026 (3 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-6973 CVE-2025-4428 CVE-2025-4427 CVE-2023-35082 CVE-2023-35078
CVE ID :CVE-2026-36387 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-36388 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored in the application and later rendered in the doctor s interface. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-36341 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-63703 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-65122 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :Regex Denial of Service in youtube-regex npm package through version 1.0.5. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-63704 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root Access CISA has issued an urgent warning regarding a critical vulnerability in Palo Alto Networks PAN-OS. Tracked as CVE-2026-0300, this severe security flaw was recently added to CISA’s Known Exploited Vuln ... Read more Published Date: May 07, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-0300
New Cisco Network Vulnerability Let Remote Attacker Cause DoS Attack Cisco has issued a critical security advisory regarding a high-severity vulnerability impacting its Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO). Tracked formally as CVE- ... Read more Published Date: May 07, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20188 CVE-2026-27174
Pagina 1796 di 3064