Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37770 risultati

News
Linux Kernel 0-Day “Copy Fail” Roots Every Major Distribution Since 2017

Linux Kernel 0-Day “Copy Fail” Roots Every Major Distribution Since 2017 A critical zero-day vulnerability in the Linux kernel has been publicly disclosed, enabling any unprivileged local user to obtain root access on virtually every major Linux distribution shipped since ... Read more Published Date: Apr 30, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431 CVE-2022-0847 CVE-2016-5195

CVEfeed Newsroom30 apr 2026
News
High-Severity RCE and XSS Flaws Found in Popular CI/CD Jenkins Plugins

High-Severity RCE and XSS Flaws Found in Popular CI/CD Jenkins Plugins The Jenkins project has released a security advisory, addressing several vulnerabilities across its plugin ecosystem. The fixes cover a range of threats, from remote code execution (RCE) and path trav ... Read more Published Date: Apr 30, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom30 apr 2026
VulnerabilitàAlta
CVE-2026-7469 - Tenda 4G300 DelFil sub_425A28 command injection

CVE ID :CVE-2026-7469 Published : April 30, 2026, 2:16 a.m. | 4 hours, 2 minutes ago Description :A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7468 (CVSS 7.3)

A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)30 apr 2026
VulnerabilitàAlta
CVE-2026-7468 - 1024-lab smart-admin Demo Site index.html access control

CVE ID :CVE-2026-7468 Published : April 30, 2026, 1:16 a.m. | 5 hours, 2 minutes ago Description :A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
VulnerabilitàAlta
CVE-2026-7447 - SourceCodester Pet Grooming Management Software update_customer.php sql injection

CVE ID :CVE-2026-7447 Published : April 30, 2026, 1:16 a.m. | 5 hours, 2 minutes ago Description :A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the argument type/length/business parameter validity causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
News
SonicWall Issues Fixes for SonicOS Vulnerabilities

SonicWall Issues Fixes for SonicOS Vulnerabilities SonicWall has released a critical security advisory addressing three distinct vulnerabilities in SonicOS that could allow attackers to bypass access controls, traverse restricted paths, or crash firew ... Read more Published Date: Apr 30, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom30 apr 2026
News
Exploit Exposed: Public PoC Disclosed for Critical Root RCE in ASUSTOR ADM (CVE-2026-6644)

Exploit Exposed: Public PoC Disclosed for Critical Root RCE in ASUSTOR ADM (CVE-2026-6644) A critical vulnerability was found in ASUSTOR ADM, the operating system powering ASUSTOR’s Network Attached Storage (NAS) devices. Discovered and reported by security researcher uky, the flaw—tracked ... Read more Published Date: Apr 30, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom30 apr 2026
VulnerabilitàAlta
CVE-2026-7446 (CVSS 7.3)

A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 1.0.1 is able to mitigate this issue. The patch is identified as 141335da044e53c3f5b315e0386e01238405b771. It is advisable to upgrade the affected component.

NVD (NIST)30 apr 2026
VulnerabilitàAlta
CVE-2026-7446 - VetCoders mcp-server-semgrep MCP index.ts create_rule os command injection

CVE ID :CVE-2026-7446 Published : April 30, 2026, 12:16 a.m. | 6 hours, 1 minute ago Description :A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 1.0.1 is able to mitigate this issue. The patch is identified as 141335da044e53c3f5b315e0386e01238405b771. It is advisable to upgrade the affected component. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 apr 2026
News
Linux cryptographic code flaw offers fast route to root

Linux cryptographic code flaw offers fast route to root Developers of major Linux distributions have begun shipping patches to address a local privilege escalation (LPE) vulnerability arising from a logic flaw. The newly disclosed LPE, dubbed Copy Fail (CV ... Read more Published Date: Apr 30, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431

CVEfeed Newsroom30 apr 2026
VulnerabilitàAlta
CVE-2026-7445 - ZachHandley ZMCPTools MCP Log Resource ResourceManager.ts path traversal

CVE ID :CVE-2026-7445 Published : April 30, 2026, 12:16 a.m. | 6 hours, 1 minute ago Description :A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP Log Resource Handler. The manipulation of the argument dirname leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026

Pagina 1987 di 3148

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.