Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

News
Critical Spring Cloud Config Flaws Expose Arbitrary Files and GCP Secrets

Critical Spring Cloud Config Flaws Expose Arbitrary Files and GCP Secrets The Spring Cloud Config project, a vital component for centralizing external configuration in distributed systems, has released a series of high-impact security updates. The release addresses four dis ... Read more Published Date: May 07, 2026 (16 hours, 15 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
News
Bitcoin Core Fixes High-Severity Remote Crash Vulnerability

Bitcoin Core Fixes High-Severity Remote Crash Vulnerability Bitcoin Core developers have released a critical fix for a long-standing vulnerability that could have allowed an attacker to remotely crash nodes across the network. The flaw, tracked as CVE-2024-529 ... Read more Published Date: May 07, 2026 (16 hours, 23 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
News
State-Sponsored Actors Weaponize Critical PAN-OS Zero-Day for Root

State-Sponsored Actors Weaponize Critical PAN-OS Zero-Day for Root Palo Alto Networks has released a high-priority security advisory and a detailed intelligence report following the discovery of a critical buffer overflow vulnerability in its PAN-OS software. Tracked ... Read more Published Date: May 07, 2026 (14 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
News
Chrome’s Security Overhaul: 127 Fixes and $100k+ in Bounties Power the New Chrome 148 Stable Release

Chrome’s Security Overhaul: 127 Fixes and $100k+ in Bounties Power the New Chrome 148 Stable Release The Google Chrome team has officially promoted Chrome 148 to the stable channel for Windows, Mac, and Linux users. This massive update—version 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows ... Read more Published Date: May 07, 2026 (14 hours, 39 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
VulnerabilitàAlta
CVE-2026-6222 - Forminator Forms <= 1.51.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'forminator_action' Parameter

CVE ID :CVE-2026-6222 Published : May 7, 2026, 1:25 a.m. | 59 minutes ago Description :The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page` (admin/abstracts/class-admin-module-edit-page.php) dispatching sensitive module-management actions — including export, delete, clone, delete-entries, publish/draft, and bulk variants — after only a nonce check, without ever verifying that the current user holds the `manage_forminator_modules` capability. The nonce used (`forminator_form_request`) is unconditionally embedded in the global `forminatorData` JavaScript object and localized on every Forminator admin page, including Templates and Reports pages accessible to users who explicitly lack module-management permissions. Because `processRequest()` is invoked during the `admin_menu` action hook — which fires before WordPress enforces page-level capability checks — a user whose Forminator role is restricted to Templates or Reports can craft a valid POST request targeting any published module and successfully trigger the vulnerable actions. This makes it possible for authenticated attackers with subscriber-level access (or any custom low-privilege Forminator role) to export the complete internal configuration of arbitrary forms/polls/quizzes (including notification routing, integration credentials, and conditional logic), delete modules, delete all submissions/votes, clone modules, or bulk-change publish/draft status. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
News
Critical Redis Patches Fix RCE and Memory Corruption Flaws

Critical Redis Patches Fix RCE and Memory Corruption Flaws The popular in-memory data structure store Redis has released a series of security updates to address five significant vulnerabilities that could lead to Remote Code Execution (RCE). These flaws, prim ... Read more Published Date: May 07, 2026 (15 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
VulnerabilitàAlta
CVE-2026-44597 - Tor Tor Out-of-Bounds Read

CVE ID :CVE-2026-44597 Published : May 7, 2026, 1:16 a.m. | 1 hour, 8 minutes ago Description :Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-40003 - USB-based arbitrary memory write vulnerability in ZTE ZX297520V3 soc BootROM

CVE ID :CVE-2026-40003 Published : May 7, 2026, 1:15 a.m. | 1 hour, 9 minutes ago Description :ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
News
Triple Critical Threat: Apache Wicket Patch Fixes Path Traversal, Session Hijacking, and Resource Bypass

Triple Critical Threat: Apache Wicket Patch Fixes Path Traversal, Session Hijacking, and Resource Bypass The Apache Wicket project, a popular open-source Java framework prized for its clean separation of HTML markup and Java logic, has released an urgent security update to address four significant vulner ... Read more Published Date: May 07, 2026 (13 hours, 24 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
VulnerabilitàAlta
CVE-2026-6278 - CVE-2019-1905: Cisco WebEx Meeting Center Unvalidated Redirect

CVE ID :CVE-2026-6278 Published : May 6, 2026, 11:16 p.m. | 3 hours, 8 minutes ago Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026
VulnerabilitàAlta
CVE-2026-3291 - Samsung Print Service Plugin – Potential Information Disclosure

CVE ID :CVE-2026-3291 Published : May 6, 2026, 10:16 p.m. | 4 hours, 8 minutes ago Description :Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026
VulnerabilitàAlta
CVE-2026-40243 - Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonation

CVE ID :CVE-2026-40243 Published : May 6, 2026, 9:16 p.m. | 5 hours, 8 minutes ago Description :Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with custom peer-certificate verification logic. That replacement verifier does not anchor trust in the configured CA certificate. Instead, it constructs the verification root set from certificates supplied by the peer during the handshake, so the configured CA is parsed but not used as the trust anchor for the final verification decision. In OVN-enabled deployments that use these SSL database connection paths, an attacker able to impersonate or intercept the OVN endpoint on the management network can present a rogue self-signed certificate chain, and Incus will accept this certificate as valid. This issue defeats the intended CA-based trust model for OVN database connections and permits endpoint impersonation by an active attacker in a suitable network position. This issue is fixed in version 7.0.0. Severity: 2.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026

Pagina 1809 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.