Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

VulnerabilitàAlta
CVE-2026-7413 - Persistent undocumented backdoor access in Yarbo robot

CVE ID :CVE-2026-7413 Published : May 7, 2026, 5:15 p.m. | 1 hour, 9 minutes ago Description :A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-7415 - Open MQTT orchestration without read/write ACLs in Yarbo robot firmware

CVE ID :CVE-2026-7415 Published : May 7, 2026, 5:15 p.m. | 1 hour, 9 minutes ago Description :The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-7414 - Hardcoded credentials in Yarbo robot firmware

CVE ID :CVE-2026-7414 Published : May 7, 2026, 5:15 p.m. | 1 hour, 9 minutes ago Description :Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
News
New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks

New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks Ivanti has issued a critical security advisory for its Endpoint Manager Mobile (EPMM) product, disclosing multiple actively exploited vulnerabilities, including CVE-2026-6973, and urging all on-premis ... Read more Published Date: May 07, 2026 (3 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-6973 CVE-2025-4428 CVE-2025-4427 CVE-2023-35082 CVE-2023-35078

CVEfeed Newsroom07 mag 2026
VulnerabilitàAlta
CVE-2026-36387 - Codeastro Membership Management System Remote File Upload RCE

CVE ID :CVE-2026-36387 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-36388 - "PHPGurukal Hospital Management System XSS"

CVE ID :CVE-2026-36388 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored in the application and later rendered in the doctor s interface. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-36341 - Webkul Krayin CRM Cross-Site Scripting (XSS)

CVE ID :CVE-2026-36341 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2025-63703 - "npm parse-ini Prototype Pollution"

CVE ID :CVE-2025-63703 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2025-65122 - YouTube Regex Denial of Service Vulnerability

CVE ID :CVE-2025-65122 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :Regex Denial of Service in youtube-regex npm package through version 1.0.5. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2025-63704 - "Query-Parser-String NPM Prototype Pollution Vulnerability"

CVE ID :CVE-2025-63704 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
News
CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root Access

CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root Access CISA has issued an urgent warning regarding a critical vulnerability in Palo Alto Networks PAN-OS. Tracked as CVE-2026-0300, this severe security flaw was recently added to CISA’s Known Exploited Vuln ... Read more Published Date: May 07, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-0300

CVEfeed Newsroom07 mag 2026
News
New Cisco Network Vulnerability Let Remote Attacker Cause DoS Attack

New Cisco Network Vulnerability Let Remote Attacker Cause DoS Attack Cisco has issued a critical security advisory regarding a high-severity vulnerability impacting its Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO). Tracked formally as CVE- ... Read more Published Date: May 07, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20188 CVE-2026-27174

CVEfeed Newsroom07 mag 2026

Pagina 1796 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.