Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37580 risultati

VulnerabilitàAlta
CVE-2026-40686 - Exim UTF-8 Out-of-Bounds Read Information Disclosure

CVE ID :CVE-2026-40686 Published : April 30, 2026, 10:16 p.m. | 2 hours, 2 minutes ago Description :In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-40687 - Exim SPA Authentication Driver Uninitialized Memory Disclosure

CVE ID :CVE-2026-40687 Published : April 30, 2026, 10:16 p.m. | 2 hours, 2 minutes ago Description :In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-40684 - Exim DNS Record Processing Denial of Service

CVE ID :CVE-2026-40684 Published : April 30, 2026, 10:16 p.m. | 2 hours, 2 minutes ago Description :In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-3345 - Path Traversal and Arbitrary File Write Vulnerability in IBM Langflow Desktop API v2 File Upload Endpoint

CVE ID :CVE-2026-3345 Published : April 30, 2026, 10:16 p.m. | 2 hours, 2 minutes ago Description :IBM Langflow Desktop Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-1577 - IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries

CVE ID :CVE-2026-1577 Published : April 30, 2026, 9:49 p.m. | 29 minutes ago Description :IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2025-36122 - IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic

CVE ID :CVE-2025-36122 Published : April 30, 2026, 9:48 p.m. | 29 minutes ago Description :IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2025-14688 - IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations

CVE ID :CVE-2025-14688 Published : April 30, 2026, 9:48 p.m. | 30 minutes ago Description :IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-2311 - IBM i is affected by a privilege escalation vulnerability in Web Administration GUI []

CVE ID :CVE-2026-2311 Published : April 30, 2026, 10:16 p.m. | 2 hours, 2 minutes ago Description :IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check. A malicious actor could cause user-controlled code to run with administrator privilege. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2025-36180 - Inadequate Pod Communication Restrictions, affects watsonx.data

CVE ID :CVE-2025-36180 Published : April 30, 2026, 9:28 p.m. | 50 minutes ago Description :IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7435 (CVSS 7.2)

SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic endpoint to execute arbitrary SQL statements, leading to unauthorized database access, data disclosure, authentication bypass, data modification, or complete database compromise.

NVD (NIST)30 apr 2026
VulnerabilitàAlta
CVE-2026-7435 - SSCMS v7.4.0 SQL Injection via stl:sqlContent queryString

CVE ID :CVE-2026-7435 Published : April 30, 2026, 9:16 p.m. | 1 hour, 2 minutes ago Description :SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic endpoint to execute arbitrary SQL statements, leading to unauthorized database access, data disclosure, authentication bypass, data modification, or complete database compromise. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7501 - LinkStackOrg LinkStack UserController.php editPage cross site scripting

CVE ID :CVE-2026-7501 Published : April 30, 2026, 9:16 p.m. | 1 hour, 2 minutes ago Description :A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a pull request but has not reacted yet. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026

Pagina 1958 di 3132

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.