News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36849 risultati
CVE ID :CVE-2026-42375 Published : May 4, 2026, 5:16 p.m. | 1 hour, 4 minutes ago Description :D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir600l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login binary uses strcmp() to validate credentials. Successful authentication grants an unauthenticated attacker on the local network a root shell with full administrative control. The device has reached End-of-Life (EOL) and will not receive patches. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42079 Published : May 4, 2026, 5:16 p.m. | 1 hour, 4 minutes ago Description :PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the environment_params field. Attackers can bypass Jinja2 SandboxedEnvironment protections by setting the finalize parameter to any importable Python callable such as subprocess.getoutput, which is invoked on every rendered expression outside the sandbox's call interception mechanism, achieving remote code execution as the NetBox service user.
Buffer overflow due to incorrect authorization in PLC FW
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
Cyber Brief 26-05 - April 2026 Cyber Brief (April 2026)May 4, 2026 – Version: 1TLP:CLEARExecutive summaryWe analysed 366 open source reports for this Cyber Brief1.Relating to cyber policy and law enforcement, the Council of the Eur ... Read more Published Date: May 04, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32201 CVE-2026-35616 CVE-2025-55182 CVE-2025-59528
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation (formerly Central) ... Read more Published Date: May 04, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-5174 CVE-2026-4670 CVE-2026-33626 CVE-2026-32202 CVE-2026-3854
CVE ID :CVE-2026-40563 Published : May 4, 2026, 3:17 p.m. | 1 hour, 3 minutes ago Description :Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data Affect Version: This issue affects Apache Atlas: from 0.8 through 2.4.0. For the affect version >= 2.0, vulnerability is only when Atlas is deployed with below non-default configuration. atlas.dsl.executor.traversal=false Mitigation: Users are recommended to upgrade to version 2.5.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6501 Published : May 4, 2026, 3:16 p.m. | 1 hour, 4 minutes ago Description :Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenDocument: 1.5. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1857 di 3071