Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

VulnerabilitàAlta
CVE-2026-41648 - Incus: Unbounded YAML Metadata Decode via Parsing

CVE ID :CVE-2026-41648 Published : May 7, 2026, 1:05 p.m. | 1 hour, 19 minutes ago Description :Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML files parsed without any size restrictions. This was making it easy for an authenticated user to provide a crafted image or backup tarball that when parsed by Incus would lead to a very large YAML document being loaded into memory, potentially causing the entire server to run out of memory. This issue has been patched in version 7.0.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-41647 - Incus: Nil-Pointer Dereference via S3 Bucket Import

CVE ID :CVE-2026-41647 Published : May 7, 2026, 1:02 p.m. | 1 hour, 22 minutes ago Description :Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file. This issue has been patched in version 7.0.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
News
How Cloudflare responded to the “Copy Fail” Linux vulnerability

How Cloudflare responded to the “Copy Fail” Linux vulnerability How Cloudflare responded to the “Copy Fail” Linux vulnerability2026-05-078 min readOn April 29, 2026, a Linux kernel local privilege escalation vulnerability was publicly disclosed under the name "Cop ... Read more Published Date: May 07, 2026 (1 day, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431

CVEfeed Newsroom07 mag 2026
VulnerabilitàCritica
CVE-2026-6508 (CVSS 9.8)

Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liderahenk: from 2.0.1 before 2.0.2.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-6508 - RCE in TUBITAK BILGEM's Liderahenk

CVE ID :CVE-2026-6508 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liderahenk: from 2.0.1 before 2.0.2. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-42010 (CVSS 7.1)

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-42010 - Gnutls: gnutls: authentication bypass via nul character in username

CVE ID :CVE-2026-42010 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-3953 (CVSS 8.8)

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Proticaret E-Commerce allows Cross-Site Scripting (XSS), Reflected XSS. This issue affects Proticaret E-Commerce: from v5.0.0 before V 6.0.1767.1383.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-3953 - Reflected XSS in Gosoft Software's Proticaret E-Commerce

CVE ID :CVE-2026-3953 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Proticaret E-Commerce allows Cross-Site Scripting (XSS), Reflected XSS. This issue affects Proticaret E-Commerce: from v5.0.0 before V 6.0.1767.1383. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-8080 - MISP core - Stored XSS in MISP template (old engine) element attribute type

CVE ID :CVE-2026-8080 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in the template element attribute handling logic. The application accepted arbitrary values for the TemplateElementAttribute type and category fields without validating them against the known MISP attribute type and category definitions. An attacker with permission to create or modify template element attributes could store a crafted type value. This affects the old templating (not more accessible in 2.5.37) engine from MISP which will be removed in 2.5.38 Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
News
Cisco Unity Connection Flaws Enable Full System Takeover

Cisco Unity Connection Flaws Enable Full System Takeover Cisco has issued a high-priority security advisory regarding multiple vulnerabilities in Cisco Unity Connection that could allow adversaries to seize control of affected systems or orchestrate sophist ... Read more Published Date: May 07, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
News
Lek in firewalls Palo Alto Networks sinds begin april misbruikt bij aanvallen

Lek in firewalls Palo Alto Networks sinds begin april misbruikt bij aanvallen Een kritieke kwetsbaarheid in firewalls van Palo Alto Networks is sinds begin april misbruikt bij aanvallen, zo heeft het securitybedrijf zelf bekendgemaakt. Updates voor het beveiligingslek zijn nog ... Read more Published Date: May 07, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-0300

CVEfeed Newsroom07 mag 2026

Pagina 1801 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.