News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36763 risultati
CVE ID :CVE-2026-41644 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) vulnerability in monetr's Lunch Flow integration allowed any authenticated user on a self-hosted instance to cause the monetr server to issue HTTP GET requests to arbitrary URLs supplied by the caller, with the response body from non-200 upstream responses reflected back in the API error message. This issue has been patched in version 1.12.5. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41643 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42285 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improperly handles the internal state transition to a "withdraw" action, leading to a nil pointer dereference in the AdjRib.Update function. This causes the entire GoBGP process to crash, resulting in a complete loss of service availability. This issue has been patched in version 4.5.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41642 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
WatchGuard Agent Vulnerabilities Let Attackers Grant Full SYSTEM Privileges on Windows WatchGuard has released urgent security updates to address multiple high-severity vulnerabilities affecting the WatchGuard Agent on Windows. The most critical of these flaws allows authenticated local ... Read more Published Date: May 07, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-6788 CVE-2026-6787 CVE-2026-41288 CVE-2026-41286 CVE-2026-41287
Critical Redis Vulnerabilities Enables Remote Code Execution Attacks Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to c ... Read more Published Date: May 07, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-25589 CVE-2026-25588 CVE-2026-25243 CVE-2026-23631 CVE-2026-23479
Palo Alto Networks Firewall Zero-Day RCE Vulnerability Exploited in the Wild Since April A critical zero-day vulnerability in Palo Alto Networks PAN-OS software has been actively exploited by a likely state-sponsored threat actor since at least April 2026, the company revealed in a securi ... Read more Published Date: May 07, 2026 (22 hours, 47 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-0300
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories Bad week.Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped into Discord channels ... Read more Published Date: May 07, 2026 (22 hours, 53 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-7412 CVE-2026-7411 CVE-2026-4670 CVE-2026-33626 CVE-2026-32202 CVE-2026-39987 CVE-2026-2298 CVE-2026-3854 CVE-2026-22586 CVE-2026-22585 CVE-2026-22583 CVE-2026-22582
CVE ID :CVE-2026-33589 Published : May 7, 2026, 11:16 a.m. | 1 hour, 9 minutes ago Description :Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-33588 Published : May 7, 2026, 11:16 a.m. | 1 hour, 9 minutes ago Description :Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-33587 Published : May 7, 2026, 11:16 a.m. | 1 hour, 9 minutes ago Description :Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-28201 Published : May 7, 2026, 11:16 a.m. | 1 hour, 9 minutes ago Description :An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1802 di 3064