Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36931 risultati

VulnerabilitàAlta
CVE-2026-43861 - Mutt URL Decode Buffer Overflow Vulnerability

CVE ID :CVE-2026-43861 Published : May 4, 2026, 7:16 a.m. | 5 hours, 4 minutes ago Description :mutt before 2.3.2 does not check for '\0' in url_pct_decode. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-43862 - Mutt IMAP GSS Mishandling Vulnerability

CVE ID :CVE-2026-43862 Published : May 4, 2026, 7:16 a.m. | 5 hours, 4 minutes ago Description :In mutt before 2.3.2, the imap_auth_gss security level is mishandled. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-29200 - Comet Backup Tenant Impersonation IDOR

CVE ID :CVE-2026-29200 Published : May 4, 2026, 7:16 a.m. | 3 hours, 4 minutes ago Description :A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-43860 - Mutt IMAP Auth Cram MD5 Hash Truncation Vulnerability

CVE ID :CVE-2026-43860 Published : May 4, 2026, 7:16 a.m. | 5 hours, 4 minutes ago Description :mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-20451 - Samsung Linux Base Console (SLBC) Type Confusion Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20451 Published : May 4, 2026, 7:15 a.m. | 1 hour, 4 minutes ago Description :In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-20448 - Geniezone Missing Permission Check Privilege Escalation Vulnerability

CVE ID :CVE-2026-20448 Published : May 4, 2026, 7:15 a.m. | 1 hour, 4 minutes ago Description :In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-20449 - "Modem HEAP Buffer Overflow Vulnerability"

CVE ID :CVE-2026-20449 Published : May 4, 2026, 7:15 a.m. | 1 hour, 4 minutes ago Description :In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue ID: MSV-6148. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-20450 - "Huawei Modem Remote Denial of Service Vulnerability"

CVE ID :CVE-2026-20450 Published : May 4, 2026, 7:15 a.m. | 1 hour, 4 minutes ago Description :In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620; Issue ID: MSV-6100. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-29199 - phpBB Host Header Injection Vulnerability

CVE ID :CVE-2026-29199 Published : May 4, 2026, 7:15 a.m. | 1 hour, 4 minutes ago Description :phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Host header (e.g. through misconfigured host setup or missing header validation by the webserver) can cause password reset emails to contain a link pointing to an attacker-controlled domain, potentially leading to account takeover. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-20447 - Geniezone Privilege Escalation Vulnerability

CVE ID :CVE-2026-20447 Published : May 4, 2026, 7:15 a.m. | 1 hour, 4 minutes ago Description :In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-7743 - CodeAstro Online Classroom studentdetails sql injection

CVE ID :CVE-2026-7743 Published : May 4, 2026, 8:16 a.m. | 6 hours, 4 minutes ago Description :A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdetails. The manipulation of the argument deleteid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026
VulnerabilitàAlta
CVE-2026-7742 - CodeAstro Online Classroom facultylogin sql injection

CVE ID :CVE-2026-7742 Published : May 4, 2026, 8:16 a.m. | 6 hours, 4 minutes ago Description :A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /OnlineClassroom/facultylogin. Executing a manipulation of the argument fid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 mag 2026

Pagina 1870 di 3078

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.