Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37121 risultati

VulnerabilitàAlta
CVE-2026-7674 - Shenzhen Libituo Technology LBT-T300-HW1 Web Management start_single_service buffer overflow

CVE ID :CVE-2026-7674 Published : May 3, 2026, 2:17 a.m. | 10 hours, 2 minutes ago Description :A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_single_service of the component Web Management Interface. Executing a manipulation of the argument vpn_pptp_server/vpn_l2tp_server can lead to buffer overflow. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-40561 - Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence

CVE ID :CVE-2026-40561 Published : May 3, 2026, 1:15 a.m. | 11 hours, 4 minutes ago Description :Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starlet incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7673 - crmeb_java Admin Upload UploadServiceImpl.java unrestricted upload

CVE ID :CVE-2026-7673 Published : May 3, 2026, 2:17 a.m. | 10 hours, 2 minutes ago Description :A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin Upload. Performing a manipulation of the argument model results in unrestricted upload. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7672 - youlaitech youlai-boot Users Endpoint UserController.java getUserList sql injection

CVE ID :CVE-2026-7672 Published : May 3, 2026, 12:16 a.m. | 12 hours, 3 minutes ago Description :A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.java of the component Users Endpoint. Such manipulation of the argument order leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7671 - CodeWise Tornet Scooter Mobile App TwoFactor excessive authentication

CVE ID :CVE-2026-7671 Published : May 3, 2026, 12:16 a.m. | 10 hours, 3 minutes ago Description :A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unknown function of the file /TwoFactor. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7670 (CVSS 7.3)

A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/UserSel.aspx. This manipulation of the argument DeptIDList causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)02 mag 2026
VulnerabilitàAlta
CVE-2026-6481 - Apache HTTP Server Remote Code Execution

CVE ID :CVE-2026-6481 Published : May 2, 2026, 11:16 p.m. | 11 hours, 3 minutes ago Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7670 - Jinher OA UserSel.aspx sql injection

CVE ID :CVE-2026-7670 Published : May 2, 2026, 11:16 p.m. | 11 hours, 3 minutes ago Description :A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/UserSel.aspx. This manipulation of the argument DeptIDList causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7669 - sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer deserialization

CVE ID :CVE-2026-7669 Published : May 2, 2026, 10:16 p.m. | 10 hours, 3 minutes ago Description :A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7668 (CVSS 7.3)

A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)02 mag 2026
VulnerabilitàAlta
CVE-2026-7668 - MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds

CVE ID :CVE-2026-7668 Published : May 2, 2026, 9:16 p.m. | 11 hours, 3 minutes ago Description :A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
News
Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability

Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability A sophisticated adversarial campaign targeting South-East Asian government and military infrastructure, combining rapid exploitation of a critical cPanel authentication bypass with a custom zero-day e ... Read more Published Date: May 02, 2026 (2 days, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-41940

CVEfeed Newsroom02 mag 2026

Pagina 1895 di 3094

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.