Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45328 risultati

VulnerabilitàAlta
CVE-2026-92530 - Use of Less Trusted Source in GitLab

CVE ID :CVE-2026-92530 Published : Sept. 24, 2026, 12:17 a.m. | 2 hours, 31 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request authorship and attribute content to arbitrary existing users on the target instance due to improper reliance on ephemeral cache state during Direct Transfer imports. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-92628 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab

CVE ID :CVE-2026-92628 Published : Sept. 24, 2026, 12:17 a.m. | 2 hours, 31 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect user context. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-92874 - Incorrect Authorization in GitLab

CVE ID :CVE-2026-92874 Published : Sept. 24, 2026, 12:17 a.m. | 2 hours, 31 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to perform actions beyond the intended scope of that token due to improper authorization checks. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-93577 - Integer Overflow or Wraparound in GitLab

CVE ID :CVE-2026-93577 Published : Sept. 24, 2026, 12:17 a.m. | 2 hours, 31 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-96739 - SEMCMS KindEditor Upload upload_json.php cross site scripting

CVE ID :CVE-2026-96739 Published : Sept. 24, 2026, 12:17 a.m. | 4 hours, 28 minutes ago Description :A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-82370 - Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service

CVE ID :CVE-2026-82370 Published : Sept. 24, 2026, 12:17 a.m. | 30 minutes ago Description :Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management instructions. This could allow an attacker to alter Fibre Channel fabric switch configurations or manipulate application container runtimes. This vulnerability affects Brocade SANnav versions before 3.0.1a. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-96764 - kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources

CVE ID :CVE-2026-96764 Published : Sept. 24, 2026, 1:16 a.m. | 3 hours, 28 minutes ago Description :A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-96763 - kvcache-ai mooncake MountSegment Request Processing segment.cpp access control

CVE ID :CVE-2026-96763 Published : Sept. 24, 2026, 1:16 a.m. | 3 hours, 28 minutes ago Description :A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-96680 - ByteDance Coze Scraper Extension External Message index.js chrome.runtime.onMessageExternal.addListener authorization

CVE ID :CVE-2026-96680 Published : Sept. 23, 2026, 11:18 p.m. | 1 hour, 29 minutes ago Description :A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of the component External Message Handler. The manipulation of the argument body.url/paginationConfig/xPathConfig/body.urls/xPaths results in missing authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96678 - weiqingwen spring-boot-forum Avatar Upload NewUserFormValidator.java validate path traversal

CVE ID :CVE-2026-96678 Published : Sept. 23, 2026, 11:18 p.m. | 1 hour, 29 minutes ago Description :A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of the file src/main/java/com/qingwenwei/util/NewUserFormValidator.java of the component Avatar Upload. The manipulation of the argument Username leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-70125 (CVSS 8.8)

Microsoft Outlook Remote Code Execution Vulnerability

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-70125 - Microsoft Outlook Remote Code Execution Vulnerability

CVE ID :CVE-2026-70125 Published : Sept. 23, 2026, 11:18 p.m. | 1 hour, 29 minutes ago Description :Microsoft Outlook Remote Code Execution Vulnerability Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 188 di 3778

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.