Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36961 risultati

VulnerabilitàAlta
CVE-2026-7706 - Open5GS AMF gmm-handler.c gmm_handle_service_request denial of service

CVE ID :CVE-2026-7706 Published : May 3, 2026, 11:16 p.m. | 1 hour, 3 minutes ago Description :A vulnerability has been found in Open5GS up to 2.7.7. This issue affects the function gmm_handle_service_request of the file /src/amf/gmm-handler.c of the component AMF. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7703 (CVSS 7.3)

A flaw has been found in AV Stumpfl Pixera Two Media Server up to 25.2 R2. Impacted is an unknown function of the component Websocket API. This manipulation causes code injection. The attack can be initiated remotely. The exploit has been published and may be used. Upgrading to version 25.2 R3 is recommended to address this issue. Upgrading the affected component is advised.

NVD (NIST)03 mag 2026
VulnerabilitàAlta
CVE-2026-7704 - AV Stumpfl Pixera Two Media Server Service Port 1338 path traversal

CVE ID :CVE-2026-7704 Published : May 3, 2026, 5:16 p.m. | 7 hours, 4 minutes ago Description :A vulnerability has been found in AV Stumpfl Pixera Two Media Server up to 25.1 R2. The affected element is an unknown function of the component Service Port 1338. Such manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 25.2 R3 is sufficient to fix this issue. It is advisable to upgrade the affected component. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7703 - AV Stumpfl Pixera Two Media Server Websocket API code injection

CVE ID :CVE-2026-7703 Published : May 3, 2026, 5:16 p.m. | 7 hours, 4 minutes ago Description :A flaw has been found in AV Stumpfl Pixera Two Media Server up to 25.2 R2. Impacted is an unknown function of the component Websocket API. This manipulation causes code injection. The attack can be initiated remotely. The exploit has been published and may be used. Upgrading to version 25.2 R3 is recommended to address this issue. Upgrading the affected component is advised. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7702 - toeverything AFFiNE Public Markdown Preview Endpoint :docId allowDocPreview authorization

CVE ID :CVE-2026-7702 Published : May 3, 2026, 4:15 p.m. | 8 hours, 4 minutes ago Description :A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId/:docId of the component Public Markdown Preview Endpoint. The manipulation results in authorization bypass. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7701 - Telegram Desktop Bot API url_auth_box.cpp RequestButton null pointer dereference

CVE ID :CVE-2026-7701 Published : May 3, 2026, 4:15 p.m. | 8 hours, 4 minutes ago Description :A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7700 - langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection

CVE ID :CVE-2026-7700 Published : May 3, 2026, 3:15 p.m. | 9 hours, 4 minutes ago Description :A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.p of the component LambdaFilterComponent. Executing a manipulation can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7699 - Dromara MaxKey StrUtils.java StrUtils.checkSqlInjection sql injection

CVE ID :CVE-2026-7699 Published : May 3, 2026, 3:15 p.m. | 9 hours, 4 minutes ago Description :A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file StrUtils.java. Performing a manipulation of the argument filtersfields results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7698 (CVSS 7.3)

A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of the file /Easy7/rest/systemInfo/updateDbBackupInfo. Such manipulation of the argument week leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)03 mag 2026
VulnerabilitàAlta
CVE-2026-7698 - Tiandy Easy7 Integrated Management Platform updateDbBackupInfo os command injection

CVE ID :CVE-2026-7698 Published : May 3, 2026, 2:16 p.m. | 10 hours, 3 minutes ago Description :A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of the file /Easy7/rest/systemInfo/updateDbBackupInfo. Such manipulation of the argument week leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7696 - Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform uploadH5Files unrestricted upload

CVE ID :CVE-2026-7696 Published : May 3, 2026, 1:16 p.m. | 11 hours, 4 minutes ago Description :A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7695 (CVSS 7.3)

A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)03 mag 2026

Pagina 1878 di 3081

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.