News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
37760 risultati
New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions Cybersecurity researchers have disclosed details of a Linux local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root. The high-severity vulnerability tracked as ... Read more Published Date: Apr 30, 2026 (2 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431 CVE-2026-33626 CVE-2026-32202 CVE-2026-3854 CVE-2022-0847
CVE ID :CVE-2026-42512 Published : April 30, 2026, 9:16 a.m. | 5 hours, 2 minutes ago Description :As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to overrun its buffer of environment entries. This can result in a crash, but it may be possible to leverage this bug to achieve remote code execution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42799 Published : April 30, 2026, 9:16 a.m. | 5 hours, 2 minutes ago Description :Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39457 Published : April 30, 2026, 9:16 a.m. | 5 hours, 2 minutes ago Description :When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, can trigger stack corruption. If the target application is setuid-root, then this could be used to elevate local privileges. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-35547 Published : April 30, 2026, 9:16 a.m. | 5 hours, 2 minutes ago Description :When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-22070 Published : April 30, 2026, 9:16 a.m. | 5 hours, 2 minutes ago Description :ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41016 Published : April 30, 2026, 10:16 a.m. | 4 hours, 2 minutes ago Description :Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS upgrade, and capture the SMTP credentials sent during the subsequent `login()` call. Users are advised to upgrade to the `apache-airflow-providers-smtp` version that contains the fix. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
NVIDIA Patches High-Severity “Prompt Injection” Flaw in NemoClaw NVIDIA has released a critical software update for NVIDIA NemoClaw, addressing a high-severity vulnerability that could allow remote attackers to bypass security controls and exfiltrate sensitive host ... Read more Published Date: Apr 30, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-42800 Published : April 30, 2026, 10:16 a.m. | 6 hours, 2 minutes ago Description :NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Kritiek beveiligingslek in cPanel en WHM actief misbruikt bij aanvallen Een kritiek beveiligingslek in cPanel en WHM waardoor ongeauthenticeerde aanvallers admin-toegang tot systemen kunnen krijgen wordt actief misbruikt bij aanvallen. Beveiligingsupdates zijn sinds 28 ap ... Read more Published Date: Apr 30, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-41940
Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild In early 2026, two critical authentication bypass vulnerabilities in the popular open-source Qinglong task scheduler were actively exploited by hackers. According to Snyk security reports, unauthentic ... Read more Published Date: Apr 30, 2026 (2 days, 2 hours ago) Vulnerabilities has been mentioned in this article.
CISA Warns of ConnectWise ScreenConnect Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a severe vulnerability in ConnectWise ScreenConnect. On April 28, 2026, CISA officially added th ... Read more Published Date: Apr 30, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-1708
Pagina 1982 di 3147