Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36912 risultati

VulnerabilitàAlta
CVE-2026-43864 - Mutt NULL Pointer Dereference Vulnerability

CVE ID :CVE-2026-43864 Published : May 4, 2026, 7:16 a.m. | 5 hours, 4 minutes ago Description :mutt before 2.3.2 has a show_sig_summary NULL pointer dereference. Severity: 2.5 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-43863 - Mutt GPGME Infinite Loop Vulnerability

CVE ID :CVE-2026-43863 Published : May 4, 2026, 7:16 a.m. | 5 hours, 4 minutes ago Description :mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-7738 - puchunjie doc-tools-mcp MCP mcp-server.ts open_document path traversal

CVE ID :CVE-2026-7738 Published : May 4, 2026, 7:16 a.m. | 7 hours, 4 minutes ago Description :A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-server.ts of the component MCP Interface. The manipulation of the argument filePath results in path traversal. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-7737 - osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds

CVE ID :CVE-2026-7737 Published : May 4, 2026, 7:16 a.m. | 7 hours, 4 minutes ago Description :A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-29200 - Comet Backup Tenant Impersonation IDOR

CVE ID :CVE-2026-29200 Published : May 4, 2026, 7:16 a.m. | 3 hours, 4 minutes ago Description :A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-43862 - Mutt IMAP GSS Mishandling Vulnerability

CVE ID :CVE-2026-43862 Published : May 4, 2026, 7:16 a.m. | 5 hours, 4 minutes ago Description :In mutt before 2.3.2, the imap_auth_gss security level is mishandled. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-43861 - Mutt URL Decode Buffer Overflow Vulnerability

CVE ID :CVE-2026-43861 Published : May 4, 2026, 7:16 a.m. | 5 hours, 4 minutes ago Description :mutt before 2.3.2 does not check for '\0' in url_pct_decode. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-43859 - Mutt IMAP Auth Cram MD5 Buffer Overflow

CVE ID :CVE-2026-43859 Published : May 4, 2026, 7:16 a.m. | 5 hours, 4 minutes ago Description :mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-43860 - Mutt IMAP Auth Cram MD5 Hash Truncation Vulnerability

CVE ID :CVE-2026-43860 Published : May 4, 2026, 7:16 a.m. | 5 hours, 4 minutes ago Description :mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-20448 - Geniezone Missing Permission Check Privilege Escalation Vulnerability

CVE ID :CVE-2026-20448 Published : May 4, 2026, 7:15 a.m. | 1 hour, 4 minutes ago Description :In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-20449 - "Modem HEAP Buffer Overflow Vulnerability"

CVE ID :CVE-2026-20449 Published : May 4, 2026, 7:15 a.m. | 1 hour, 4 minutes ago Description :In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue ID: MSV-6148. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-29199 - phpBB Host Header Injection Vulnerability

CVE ID :CVE-2026-29199 Published : May 4, 2026, 7:15 a.m. | 1 hour, 4 minutes ago Description :phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Host header (e.g. through misconfigured host setup or missing header validation by the webserver) can cause password reset emails to contain a link pointing to an attacker-controlled domain, potentially leading to account takeover. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026

Pagina 1868 di 3076

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.