News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36796 risultati
CVE ID :CVE-2025-71255 Published : May 6, 2026, 2:16 a.m. | 6 hours, 6 minutes ago Description :In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-71254 Published : May 6, 2026, 2:16 a.m. | 6 hours, 6 minutes ago Description :In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-71253 Published : May 6, 2026, 2:16 a.m. | 6 hours, 6 minutes ago Description :In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-71252 Published : May 6, 2026, 2:16 a.m. | 6 hours, 6 minutes ago Description :In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-71251 Published : May 6, 2026, 2:16 a.m. | 6 hours, 6 minutes ago Description :In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Exploited in the Wild: Critical PAN-OS Buffer Overflow Grants Root Access to Palo Alto Firewalls Palo Alto Networks has issued an urgent security advisory for a critical vulnerability in its PAN-OS software that is currently being exploited in the wild. The flaw, tracked as CVE-2026-0300, is a bu ... Read more Published Date: May 06, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.
5.7 Million Users at Risk: Multiple 9.8 CVSS Breakthroughs Enable Remote Code Execution in vm2 Sandbox The popular Node.js library vm2, a sandbox designed to run untrusted code with restricted access to built-in modules, is facing a security crisis. With over 5.7 million monthly downloads, the library ... Read more Published Date: May 06, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.
Critical Flaws in Apache Thrift Threaten Multi-Language The Apache Thrift project, a cornerstone framework for building scalable cross-language services, has released a high-priority update to address a trio of vulnerabilities that threaten its diverse eco ... Read more Published Date: May 06, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-44405 Published : May 6, 2026, 12:16 a.m. | 8 hours, 6 minutes ago Description :In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm. Severity: 3.4 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40934 Published : May 5, 2026, 10:16 p.m. | 10 hours, 6 minutes ago Description :Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-28780 Published : 5. Mai 2026 22:16 | 8 Stunden, 6 Minuten ago Description :Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40110 Published : May 5, 2026, 10:16 p.m. | 10 hours, 6 minutes ago Description :Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1828 di 3067