Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37554 risultati

VulnerabilitàAlta
CVE-2026-40684 - Exim DNS Record Processing Denial of Service

CVE ID :CVE-2026-40684 Published : April 30, 2026, 10:16 p.m. | 2 hours, 2 minutes ago Description :In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-3345 - Path Traversal and Arbitrary File Write Vulnerability in IBM Langflow Desktop API v2 File Upload Endpoint

CVE ID :CVE-2026-3345 Published : April 30, 2026, 10:16 p.m. | 2 hours, 2 minutes ago Description :IBM Langflow Desktop Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-1577 - IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries

CVE ID :CVE-2026-1577 Published : April 30, 2026, 9:49 p.m. | 29 minutes ago Description :IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2025-36122 - IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic

CVE ID :CVE-2025-36122 Published : April 30, 2026, 9:48 p.m. | 29 minutes ago Description :IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2025-14688 - IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations

CVE ID :CVE-2025-14688 Published : April 30, 2026, 9:48 p.m. | 30 minutes ago Description :IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-2311 - IBM i is affected by a privilege escalation vulnerability in Web Administration GUI []

CVE ID :CVE-2026-2311 Published : April 30, 2026, 10:16 p.m. | 2 hours, 2 minutes ago Description :IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check. A malicious actor could cause user-controlled code to run with administrator privilege. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2025-36180 - Inadequate Pod Communication Restrictions, affects watsonx.data

CVE ID :CVE-2025-36180 Published : April 30, 2026, 9:28 p.m. | 50 minutes ago Description :IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7435 (CVSS 7.2)

SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic endpoint to execute arbitrary SQL statements, leading to unauthorized database access, data disclosure, authentication bypass, data modification, or complete database compromise.

NVD (NIST)30 apr 2026
VulnerabilitàAlta
CVE-2026-7501 - LinkStackOrg LinkStack UserController.php editPage cross site scripting

CVE ID :CVE-2026-7501 Published : April 30, 2026, 9:16 p.m. | 1 hour, 2 minutes ago Description :A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a pull request but has not reacted yet. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7435 - SSCMS v7.4.0 SQL Injection via stl:sqlContent queryString

CVE ID :CVE-2026-7435 Published : April 30, 2026, 9:16 p.m. | 1 hour, 2 minutes ago Description :SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic endpoint to execute arbitrary SQL statements, leading to unauthorized database access, data disclosure, authentication bypass, data modification, or complete database compromise. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-4503 (CVSS 7.5)

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.

NVD (NIST)30 apr 2026
VulnerabilitàAlta
CVE-2026-4503 - Unauthenticated Insecure Direct Object Reference (IDOR) Vulnerability in Langflow Desktop Image Download Endpoint

CVE ID :CVE-2026-4503 Published : April 30, 2026, 9:16 p.m. | 1 hour, 2 minutes ago Description :IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026

Pagina 1956 di 3130

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.