Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

VulnerabilitàAlta
CVE-2025-67202 - Sidekiq-cron XSS Vulnerability

CVE ID :CVE-2025-67202 Published : May 7, 2026, 3:16 p.m. | 1 hour, 9 minutes ago Description :Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2025-4397 - Medtronic MyCareLink Patient Monitor Data Encryption Weakness

CVE ID :CVE-2025-4397 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2025-4386 - Medtronic MyCareLink Patient Monitor Hardware Debug Port

CVE ID :CVE-2025-4386 Published : May 7, 2026, 4:16 p.m. | 2 hours, 9 minutes ago Description :Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.​ Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
News
Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials

Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials Ivanti has issued an urgent security advisory for its Endpoint Manager Mobile (EPMM) platform, formerly known as MobileIron Core, following the discovery of several high-severity vulnerabilities. Most ... Read more Published Date: May 07, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
VulnerabilitàCritica
CVE-2026-6795 (CVSS 9.6)

URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-6795 - Open Redirect in DivvyDrive Information Technologies' DivvyDrive

CVE ID :CVE-2026-6795 Published : May 7, 2026, 2:16 p.m. | 2 hours, 9 minutes ago Description :URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2025-14341 (CVSS 8.3)

Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Excessive Allocation, Flooding. This issue affects DivvyDrive: from 4.8.2.19 before 4.8.3.2.

NVD (NIST)07 mag 2026
News
PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage

PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage Palo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026. The vulnerability in question is ... Read more Published Date: May 07, 2026 (1 day, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-0300 CVE-2026-33626 CVE-2026-32202 CVE-2026-3854

CVEfeed Newsroom07 mag 2026
VulnerabilitàAlta
CVE-2026-41554 - WordPress Bricks Builder theme 1.9.2-2.2 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-41554 Published : May 7, 2026, 1:28 p.m. | 56 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder allows Reflected XSS. This issue affects Bricks Builder: from n/a through 1.9.2 to 2.2. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-41589 - Wish has SCP Path Traversal that allows arbitrary file read/write

CVE ID :CVE-2026-41589 Published : May 7, 2026, 1:17 p.m. | 1 hour, 7 minutes ago Description :Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and create directories outside the configured root directory by sending crafted filenames containing ../ sequences over the SCP protocol. This issue has been patched in version 2.0.1. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-8094 - Other issue in the WebRTC component

CVE ID :CVE-2026-8094 Published : May 7, 2026, 1:16 p.m. | 1 hour, 8 minutes ago Description :Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-8092 - Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2

CVE ID :CVE-2026-8092 Published : May 7, 2026, 1:16 p.m. | 1 hour, 8 minutes ago Description :Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, and Firefox ESR 115.35.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026

Pagina 1799 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.