News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36912 risultati
CVE ID :CVE-2025-14320 Published : May 4, 2026, 9:15 a.m. | 5 hours, 4 minutes ago Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allows Reflected XSS. This issue affects Online Support Application: from V3 through 31122025. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-29200: A 9.9 CVSS Comet Backup Flaw Granting Total Cross-Tenant Takeover Comet Backup, a prominent provider of secure backup software for IT professionals and global businesses, has issued an urgent security alert following the discovery of a critical vulnerability in its ... Read more Published Date: May 04, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article.
CISA Warns of cPanel & WHM Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw affecting widely used web hosting management platforms. CISA recently a ... Read more Published Date: May 04, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-41940
Critical MOVEit Vulnerabilities Enables Authentication Bypass Progress Software has issued a critical security bulletin for its MOVEit Automation platform. This April 2026 alert warns of two highly severe vulnerabilities that could allow attackers to bypass secu ... Read more Published Date: May 04, 2026 (23 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-5174 CVE-2026-4670
Microsoft en VS melden misbruik van Copy Fail-kwetsbaarheid Aanvallers maken actief misbruik van de Copy Fail-kwetsbaarheid in Linux, waardoor een lokale unprivileged gebruiker root kan worden, zo melden Microsoft en het Amerikaanse cyberagentschap CISA. Micro ... Read more Published Date: May 04, 2026 (23 hours, 31 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431
Criminelen verspreiden Linux-ransomware via beveiligingslek in cPanel Criminelen maken misbruik van een kritiek beveiligingslek in cPanel en WebHost Manager (WHM) om Linux-ransomware en Mirai-malware te verspreiden, zo meldt securitybedrijf Censys. Bij de aanvallen zoud ... Read more Published Date: May 04, 2026 (22 hours, 31 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-41940
CVE ID :CVE-2026-7744 Published : May 4, 2026, 8:16 a.m. | 6 hours, 4 minutes ago Description :A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassroom/addnewstudent. The manipulation of the argument fname results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7740 Published : May 4, 2026, 7:16 a.m. | 7 hours, 4 minutes ago Description :A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit::setFPS of the file tsMuxer/vvc.cpp. Such manipulation of the argument track_id leads to denial of service. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7739 Published : May 4, 2026, 7:16 a.m. | 7 hours, 4 minutes ago Description :A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::setFPS of the file /AFLplusplus/tsMuxer_prev/tsMuxer/hevc.cpp. This manipulation of the argument track_id causes denial of service. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version 4.4.0 addresses this issue. This patch is called 76d911046344a3923cbe573364197aa081944592. It is suggested to upgrade the affected component.
CVE ID :CVE-2026-7738 Published : May 4, 2026, 7:16 a.m. | 7 hours, 4 minutes ago Description :A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-server.ts of the component MCP Interface. The manipulation of the argument filePath results in path traversal. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7737 Published : May 4, 2026, 7:16 a.m. | 7 hours, 4 minutes ago Description :A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1867 di 3076