Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36816 risultati

VulnerabilitàAlta
CVE-2026-23479 - redis-server use-after-free in unblock client flow may allow remote code execution

CVE ID :CVE-2026-23479 Published : May 5, 2026, 5:17 p.m. | 1 hour, 4 minutes ago Description :Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
News
GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications

GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications GnuTLS version 3.8.13 has been officially released to patch a dozen security vulnerabilities, including critical flaws affecting secure network communications. The update is highly recommended for all ... Read more Published Date: May 05, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
News
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE

Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remot ... Read more Published Date: May 05, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-23918 CVE-2026-33626 CVE-2026-32202 CVE-2026-3854

CVEfeed Newsroom05 mag 2026
VulnerabilitàAlta
CVE-2026-7412 - Eclipse BaSyx Java Server SDK Blind HTTP Request Forgery

CVE ID :CVE-2026-7412 Published : May 5, 2026, 4:16 p.m. | 2 hours, 5 minutes ago Description :In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker can exploit this design flaw to force the BaSyx server to execute blind HTTP POST requests to arbitrary internal or external targets. This allows an attacker to bypass network segmentation and pivot into isolated internal IT/OT infrastructure or target Cloud Metadata services (IMDS). Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-7411 - Eclipse BaSyx Java Server SDK Remote Code Execution (RCE) via Path Traversal

CVE ID :CVE-2026-7411 Published : May 5, 2026, 4:16 p.m. | 2 hours, 5 minutes ago Description :In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter during a file upload operation, an attacker can bypass intended storage boundaries and write arbitrary files to any location on the host filesystem accessible by the Java process. This can lead to Remote Code Execution (RCE) and complete system compromise. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
News
Critical Weaver E-cology RCE Vulnerability Actively Exploited in Attacks

Critical Weaver E-cology RCE Vulnerability Actively Exploited in Attacks A critical unauthenticated remote code execution vulnerability in the Weaver E-cology platform is currently being actively exploited in the wild. CVE-2026-22679 carries a maximum CVSS score of 9.8 and ... Read more Published Date: May 05, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22679

CVEfeed Newsroom05 mag 2026
News
Critical Qualcomm Chipset Vulnerabilities Enables Remote Code Execution

Critical Qualcomm Chipset Vulnerabilities Enables Remote Code Execution Qualcomm Technologies has released a critical security bulletin addressing multiple severe vulnerabilities in its proprietary and open-source software. These security updates are essential for protect ... Read more Published Date: May 05, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
VulnerabilitàAlta
CVE-2026-7846 - chatchat-space Langchain-Chatchat OpenAI-Compatible File Upload API openai_routes.py files toctou

CVE ID :CVE-2026-7846 Published : May 5, 2026, 4:16 p.m. | 2 hours, 5 minutes ago Description :A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component OpenAI-Compatible File Upload API. Such manipulation of the argument file.filename leads to time-of-check time-of-use. Access to the local network is required for this attack to succeed. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 2.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-7845 - chatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes weak hash

CVE ID :CVE-2026-7845 Published : May 5, 2026, 4:16 p.m. | 2 hours, 5 minutes ago Description :A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision Chat Paste Image Handler. This manipulation of the argument paste_image.image_data causes use of weak hash. The attacker needs to be present on the local network. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 2.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-34956 - Openvswitch: open vswitch: denial of service via malformed ftp epasv command

CVE ID :CVE-2026-34956 Published : 5. Mai 2026 15:45 | 36 Minuten ago Description :A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
News
China-Aligned SHADOW-EARTH-053 Exploits Exchange Servers to Deploy ShadowPad Malware

China-Aligned SHADOW-EARTH-053 Exploits Exchange Servers to Deploy ShadowPad Malware A China-aligned threat group tracked as SHADOW-EARTH-053 has been exploiting unpatched Microsoft Exchange Server vulnerabilities to conduct cyberespionage against government and defense-linked targets ... Read more Published Date: May 05, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2021-27065 CVE-2021-26858 CVE-2021-26857 CVE-2021-26855

CVEfeed Newsroom05 mag 2026
VulnerabilitàAlta
CVE-2026-43073 - x86-64: rename misleadingly named '__copy_user_nocache()' function

CVE ID :CVE-2026-43073 Published : May 5, 2026, 4:16 p.m. | 2 hours, 5 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: x86-64: rename misleadingly named '__copy_user_nocache()' function This function was a masterclass in bad naming, for various historical reasons. It claimed to be a non-cached user copy. It is literally _neither_ of those things. It's a specialty memory copy routine that uses non-temporal stores for the destination (but not the source), and that does exception handling for both source and destination accesses. Also note that while it works for unaligned targets, any unaligned parts (whether at beginning or end) will not use non-temporal stores, since only words and quadwords can be non-temporal on x86. The exception handling means that it _can_ be used for user space accesses, but not on its own - it needs all the normal "start user space access" logic around it. But typically the user space access would be the source, not the non-temporal destination. That was the original intention of this, where the destination was some fragile persistent memory target that needed non-temporal stores in order to catch machine check exceptions synchronously and deal with them gracefully. Thus that non-descriptive name: one use case was to copy from user space into a non-cached kernel buffer. However, the existing users are a mix of that intended use-case, and a couple of random drivers that just did this as a performance tweak. Some of those random drivers then actively misused the user copying version (with STAC/CLAC and all) to do kernel copies without ever even caring about the exception handling, _just_ for the non-temporal destination. Rename it as a first small step to actually make it halfway sane, and change the prototype to be more normal: it doesn't take a user pointer unless the caller has done the proper conversion, and the argument size is the full size_t (it still won't actually copy more than 4GB in on...

CVEfeed CVE05 mag 2026

Pagina 1835 di 3068

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.