Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37760 risultati

News
Jenkins Patches High-Severity Plugin Flaws Including Path Traversal and Stored XSS

Jenkins Patches High-Severity Plugin Flaws Including Path Traversal and Stored XSS Jenkins project published a security advisory detailing patches for seven plugin vulnerabilities, including high-severity path traversal and Stored Cross-Site Scripting (XSS) flaws. Administrators mus ... Read more Published Date: Apr 30, 2026 (3 days, 16 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42525 CVE-2026-42524 CVE-2026-42523 CVE-2026-42522 CVE-2026-42521 CVE-2026-42520 CVE-2026-42519

CVEfeed Newsroom30 apr 2026
VulnerabilitàAlta
CVE-2026-7163 - Assisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosure

CVE ID :CVE-2026-7163 Published : April 30, 2026, 2:16 p.m. | 2 hours, 1 minute ago Description :A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials download endpoint (GET /v2/clusters/{cluster_id}/credentials, which returns the kubeadmin password) and the kubeconfig download endpoint are operational in AUTH_TYPE=local mode, the only authentication mode available in on-premises ACM/MCE hub deployments. The local authenticator unconditionally grants full administrative access to any request bearing a valid JWT, with no per-endpoint restrictions. A valid local JWT is embedded as a plaintext query parameter in InfraEnvStatus.ISODownloadURL and is readable by any user who has get rights on an InfraEnv object in their own namespace. The affected components ship as part of Multicluster Engine (MCE). The Red Hat Advanced Cluster Management (ACM) deployments that include MCE are equally affected. This issue does not affect the hosted SaaS offering (console.redhat.com), which uses a different authentication mode. Successful exploitation gives the attacker the kubeadmin password and kubeconfig for any OpenShift cluster provisioned through the affected hub, granting unrestricted root-level administrative access to those spoke clusters. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7246 - Pallets Click contains a command injection via Unsanitized Filename "click.edit()"

CVE ID :CVE-2026-7246 Published : April 30, 2026, 2:16 p.m. | 2 hours, 1 minute ago Description :Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7402 (CVSS 8.1)

Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

NVD (NIST)30 apr 2026
VulnerabilitàAlta
CVE-2026-7399 (CVSS 8.1)

Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

NVD (NIST)30 apr 2026
VulnerabilitàAlta
CVE-2026-7402 - Improper Rate Limiting in MeWare Software's PDKS

CVE ID :CVE-2026-7402 Published : April 30, 2026, 1:16 p.m. | 3 hours, 2 minutes ago Description :Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7399 - IDOR in MeWare Software's PDKS

CVE ID :CVE-2026-7399 Published : April 30, 2026, 1:16 p.m. | 3 hours, 2 minutes ago Description :Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7382 - Information Disclosure in MeWare Software's PDKS

CVE ID :CVE-2026-7382 Published : April 30, 2026, 1:16 p.m. | 3 hours, 2 minutes ago Description :Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2024-13971 - Arbitrary File Read and Server Side Request Forgery via XML External Entities in Lobster_pro

CVE ID :CVE-2024-13971 Published : April 30, 2026, 1:16 p.m. | 3 hours, 2 minutes ago Description :Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2025-14576 - Possible QML code injection in VectorImage component

CVE ID :CVE-2025-14576 Published : April 30, 2026, 1:16 p.m. | 3 hours, 2 minutes ago Description :Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
News
CoreDNS Security Alert: Multiple High-Severity Vulnerabilities Patched in Version 1.14.3

CoreDNS Security Alert: Multiple High-Severity Vulnerabilities Patched in Version 1.14.3 CoreDNS, the flexible and chainable DNS server written in Go, has released a critical security update to address five significant vulnerabilities. These flaws, ranging from Denial-of-Service (DoS) to ... Read more Published Date: Apr 30, 2026 (3 days, 13 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom30 apr 2026
News
Copy Fail-kwetsbaarheid in Linux maakt lokale gebruiker root

Copy Fail-kwetsbaarheid in Linux maakt lokale gebruiker root Een onderzoeker heeft met behulp van een AI-tool een kwetsbaarheid in Linux gevonden waardoor een lokale unprivileged gebruiker root kan worden. Het probleem is in nagenoeg alle Linux-distributies aan ... Read more Published Date: Apr 30, 2026 (3 days, 14 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431

CVEfeed Newsroom30 apr 2026

Pagina 1980 di 3147

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.