Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37806 risultati

VulnerabilitàAlta
CVE-2026-7439 - AgentFlow Local Web API Content-Type Validation Bypass

CVE ID :CVE-2026-7439 Published : April 29, 2026, 7:16 p.m. | 1 hour, 1 minute ago Description :AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without enforcing application/json validation, allowing attackers to bypass trust-boundary enforcement on sensitive operations. Attackers can exploit this content-type validation weakness through browser-driven or local cross-origin requests to abuse the localhost API and enable attack chains against the local control plane. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP

CVE ID :CVE-2026-7424 Published : April 29, 2026, 7:16 p.m. | 1 hour, 1 minute ago Description :Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware reset) by sending a single crafted DHCPv6 packet. The issue is present whenever DHCPv6 is enabled. To mitigate this issue, users should upgrade to version V4.2.6 or V4.4.1 or newer. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
News
Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack

Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are exploiting a zero-click Windows flaw that can expose sensitive information on vulnerable systems. ... Read more Published Date: Apr 29, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32202 CVE-2026-21513 CVE-2026-21510

CVEfeed Newsroom29 apr 2026
VulnerabilitàAlta
CVE-2026-26204 - Wazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertData

CVE ID :CVE-2026-26204 Published : April 29, 2026, 5:43 p.m. | 34 minutes ago Description :Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, resulting in writing a NULL byte exactly 1 byte before the start of the buffer allocated by strdup. Due to unsigned integer underflow and pointer arithmetic wrapping, the write lands at offset -1 from the buffer, corrupting heap metadata. A malicious actor can potentially leverage this issue through a compromised agent to cause denial of service or heap corruption by injecting a specially crafted alert into the alerts log file monitored by wazuh-logcollector. This issue has been patched in version 4.14.4. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-26015 - Unauthenticated RCE in DocsGPT MCP STDIO Configuration

CVE ID :CVE-2026-26015 Published : April 29, 2026, 5:37 p.m. | 40 minutes ago Description :DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). This issue has been patched in version 0.16.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7396 - NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal

CVE ID :CVE-2026-7396 Published : April 29, 2026, 5:30 p.m. | 47 minutes ago Description :A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-5712 - IdentityIQ Role Editor Incorrect Authorization Vulnerability

CVE ID :CVE-2026-5712 Published : April 29, 2026, 5:18 p.m. | 59 minutes ago Description :This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7393 - SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload

CVE ID :CVE-2026-7393 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-6915 - Flaw in the updateUser Command May Allow Unauthorized Configuration Change

CVE ID :CVE-2026-6915 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-6914 - MD5 checksum creation may cause availability loss

CVE ID :CVE-2026-6914 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server. This issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB Server v8.0 versions prior to 8.0.21, MongoDB Server v7.0 versions prior to 7.0.32 Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7392 - SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection

CVE ID :CVE-2026-7392 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7391 - SourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection

CVE ID :CVE-2026-7391 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action=save_supplier. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026

Pagina 1996 di 3151

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.