Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

VulnerabilitàAlta
CVE-2026-41644 - monetr is vulnerable to server-side request forgery in Lunch Flow link creation and refresh

CVE ID :CVE-2026-41644 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) vulnerability in monetr's Lunch Flow integration allowed any authenticated user on a self-hosted instance to cause the monetr server to issue HTTP GET requests to arbitrary URLs supplied by the caller, with the response body from non-200 upstream responses reflected back in the API error message. This issue has been patched in version 1.12.5. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-41643 - GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

CVE ID :CVE-2026-41643 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-42285 - GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)

CVE ID :CVE-2026-42285 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improperly handles the internal state transition to a "withdraw" action, leading to a nil pointer dereference in the AdjRib.Update function. This causes the entire GoBGP process to crash, resulting in a complete loss of service availability. This issue has been patched in version 4.5.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-41642 - GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute

CVE ID :CVE-2026-41642 Published : May 7, 2026, 12:16 p.m. | 2 hours, 8 minutes ago Description :GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
News
WatchGuard Agent Vulnerabilities Let Attackers Grant Full SYSTEM Privileges on Windows

WatchGuard Agent Vulnerabilities Let Attackers Grant Full SYSTEM Privileges on Windows WatchGuard has released urgent security updates to address multiple high-severity vulnerabilities affecting the WatchGuard Agent on Windows. The most critical of these flaws allows authenticated local ... Read more Published Date: May 07, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-6788 CVE-2026-6787 CVE-2026-41288 CVE-2026-41286 CVE-2026-41287

CVEfeed Newsroom07 mag 2026
News
Critical Redis Vulnerabilities Enables Remote Code Execution Attacks

Critical Redis Vulnerabilities Enables Remote Code Execution Attacks Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to c ... Read more Published Date: May 07, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-25589 CVE-2026-25588 CVE-2026-25243 CVE-2026-23631 CVE-2026-23479

CVEfeed Newsroom07 mag 2026
News
Palo Alto Networks Firewall Zero-Day RCE Vulnerability Exploited in the Wild Since April

Palo Alto Networks Firewall Zero-Day RCE Vulnerability Exploited in the Wild Since April A critical zero-day vulnerability in Palo Alto Networks PAN-OS software has been actively exploited by a likely state-sponsored threat actor since at least April 2026, the company revealed in a securi ... Read more Published Date: May 07, 2026 (22 hours, 47 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-0300

CVEfeed Newsroom07 mag 2026
News
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories

ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories Bad week.Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped into Discord channels ... Read more Published Date: May 07, 2026 (22 hours, 53 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-7412 CVE-2026-7411 CVE-2026-4670 CVE-2026-33626 CVE-2026-32202 CVE-2026-39987 CVE-2026-2298 CVE-2026-3854 CVE-2026-22586 CVE-2026-22585 CVE-2026-22583 CVE-2026-22582

CVEfeed Newsroom07 mag 2026
VulnerabilitàAlta
CVE-2026-33589 - Arbitrary File Read via Local File Inclusion (LFI)

CVE ID :CVE-2026-33589 Published : May 7, 2026, 11:16 a.m. | 1 hour, 9 minutes ago Description :Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-33588 - Arbitrary File Write Through Path Traversal

CVE ID :CVE-2026-33588 Published : May 7, 2026, 11:16 a.m. | 1 hour, 9 minutes ago Description :Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-33587 - Remote Code Execution (RCE) via Server-Side Template Injection (SSTI)

CVE ID :CVE-2026-33587 Published : May 7, 2026, 11:16 a.m. | 1 hour, 9 minutes ago Description :Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-28201 - SurrealDB Injection on Open Notebook

CVE ID :CVE-2026-28201 Published : May 7, 2026, 11:16 a.m. | 1 hour, 9 minutes ago Description :An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026

Pagina 1802 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.