News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36882 risultati
CVE ID :CVE-2026-31205 Published : May 4, 2026, 2:16 p.m. | 2 hours, 4 minutes ago Description :Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-70069 Published : May 4, 2026, 2:16 p.m. | 2 hours, 4 minutes ago Description :An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-70067 Published : May 4, 2026, 2:16 p.m. | 2 hours, 4 minutes ago Description :Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7482 Published : May 4, 2026, 1:16 p.m. | 3 hours, 4 minutes ago Description :Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may include environment variables, API keys, system prompts, and concurrent users' conversation data, and can be exfiltrated by uploading the resulting model artifact through the /api/push endpoint to an attacker-controlled registry. The /api/create and /api/push endpoints have no authentication in the upstream distribution. Default deployments bind to 127.0.0.1, but the documented OLLAMA_HOST=0.0.0.0 configuration is widely used in practice (large public-internet exposure observed). Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-24072 Published : May 4, 2026, 1:16 p.m. | 3 hours, 4 minutes ago Description :An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-34059 Published : May 4, 2026, 1:16 p.m. | 3 hours, 4 minutes ago Description :Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Kritiek beveiligingslek in MOVEit Automation geeft aanvaller toegang tot systeem maandag 4 mei 2026, 15:14 door Redactie, 0 reactiesLaatst bijgewerkt: Vandaag, 15:28 Softwareontwikkelaar Progress waarschuwt voor een kritiek beveiligingslek in MOVEit Automation waardoor een aanvall ... Read more Published Date: May 04, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5174 CVE-2026-4670 CVE-2023-34362
CVE ID :CVE-2025-58074 Published : May 4, 2026, 2:16 p.m. | 2 hours, 4 minutes ago Description :A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Patch Now: GnuTLS Release 3.8.13 Fixes 12 Vulnerabilities The GnuTLS project, a vital secure communications library used extensively across the Linux ecosystem to implement SSL, TLS, and DTLS protocols, has issued a major security update. Version 3.8.13, rel ... Read more Published Date: May 04, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-33857 Published : May 4, 2026, 2:16 p.m. | 2 hours, 4 minutes ago Description :Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-34032 Published : May 4, 2026, 2:16 p.m. | 2 hours, 4 minutes ago Description :Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Sentry’s 9.1 CVSS SSO Flaw Lets Attackers “Link” Their Way Into Your Account Sentry, the widely used application monitoring and error-tracking platform, has disclosed a critical vulnerability in its SAML SSO implementation. Tracked as CVE-2026-42354, this flaw carries a severe ... Read more Published Date: May 04, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article.
Pagina 1862 di 3074