Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37731 risultati

VulnerabilitàAlta
CVE-2026-36761 - JeeSite Stored XSS Vulnerability

CVE ID :CVE-2026-36761 Published : April 30, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the msgContent parameter. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-36763 - SpringBlade Stored Cross-Site Scripting (XSS)

CVE ID :CVE-2026-36763 Published : April 30, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-36762 - JeeSite File Upload Path Traversal Vulnerability

CVE ID :CVE-2026-36762 Published : April 30, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem locations. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-36765 - SpringBlade XXE Code Execution Vulnerability

CVE ID :CVE-2026-36765 Published : April 30, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-36766 - Shopizer Cross-Site Scripting (XSS) Vulnerability

CVE ID :CVE-2026-36766 Published : April 30, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the getInputStream() or getReader() functions. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-33845 (CVSS 7.5)

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

NVD (NIST)30 apr 2026
VulnerabilitàAlta
CVE-2026-33845 - Gnutls: gnutls: denial of service via dtls zero-length fragment

CVE ID :CVE-2026-33845 Published : April 30, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-3832 - Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response

CVE ID :CVE-2026-3832 Published : April 30, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-3833 - Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison

CVE ID :CVE-2026-3833 Published : April 30, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-36767 - Shopizer Path Traversal File Write Vulnerability

CVE ID :CVE-2026-36767 Published : April 30, 2026, 5:16 p.m. | 3 hours, 2 minutes ago Description :A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-36764 - SpringBlade SSRF Vulnerability

CVE ID :CVE-2026-36764 Published : April 30, 2026, 5:16 p.m. | 3 hours, 2 minutes ago Description :A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-36760 - JeeSite File Upload Path Traversal Write Arbitrary Files

CVE ID :CVE-2026-36760 Published : April 30, 2026, 5:16 p.m. | 3 hours, 2 minutes ago Description :An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem locations while chunked upload is enabled. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026

Pagina 1974 di 3145

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.