Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37854 risultati

VulnerabilitàAlta
CVE-2026-7111 - Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption

CVE ID :CVE-2026-7111 Published : April 29, 2026, 3:16 p.m. | 1 hour, 1 minute ago Description :Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or on_error) and cache the Perl argument stack pointer across the call. If a callback extends the argument stack enough to trigger a reallocation, the return value is written through the stale pointer into the freed buffer, and the caller reads the original $self argument as the return value instead. Calling code that expects parsed data from getline_all receives the Text::CSV_XS object in its place, leading to logic errors or crashes. Text::CSV_XS objects used without any registered callbacks are not affected. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-5161 (CVSS 8.8)

Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack. This issue affects Pardus About: before v1.2.1.

NVD (NIST)29 apr 2026
VulnerabilitàAlta
CVE-2026-5161 - Improper Authentication in TUBITAK BILGEM's Pardus About

CVE ID :CVE-2026-5161 Published : April 29, 2026, 3:16 p.m. | 1 hour, 1 minute ago Description :Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack. This issue affects Pardus About: before v1.2.1. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-5141 (CVSS 8.8)

Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking a privileged process. This issue affects Pardus Software Center: before 1.0.3.

NVD (NIST)29 apr 2026
VulnerabilitàAlta
CVE-2026-5141 - Improper Access Control in TUBITAK BILGEM's Pardus Software Center

CVE ID :CVE-2026-5141 Published : April 29, 2026, 3:16 p.m. | 1 hour, 1 minute ago Description :Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking a privileged process. This issue affects Pardus Software Center: before 1.0.3. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-41952 - Acronis DeviceLock DLP/Acronis Cyber Protect Cloud Agent Local Privilege Escalation

CVE ID :CVE-2026-41952 Published : April 29, 2026, 3:16 p.m. | 1 hour, 1 minute ago Description :Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-25852 - Acronis DeviceLock DLP DLL Hijacking Vulnerability

CVE ID :CVE-2026-25852 Published : April 29, 2026, 3:16 p.m. | 1 hour, 1 minute ago Description :Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-36841 - TOTOLINK N200RE Command Injection Vulnerability

CVE ID :CVE-2026-36841 Published : April 29, 2026, 3:16 p.m. | 1 hour, 1 minute ago Description :TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-38992 - Cockpit MongoDB Code Execution Vulnerability

CVE ID :CVE-2026-38992 Published : April 29, 2026, 3:16 p.m. | 1 hour, 1 minute ago Description :Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-36837 - TOTOLINK A3002RU DNS Stack Overflow Vulnerability

CVE ID :CVE-2026-36837 Published : April 29, 2026, 3:16 p.m. | 1 hour, 1 minute ago Description :TOTOLINK A3002RU V3 Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-41220 - Acronis DeviceLock DLP/Cyber Protect Cloud Agent Local Privilege Escalation Vulnerability

CVE ID :CVE-2026-41220 Published : April 29, 2026, 3:16 p.m. | 1 hour, 1 minute ago Description :Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7388 - EyouCMS Template File FilemanagerLogic.php editFile code injection

CVE ID :CVE-2026-7388 Published : April 29, 2026, 4:16 p.m. | 2 hours, 1 minute ago Description :A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File Handler. Executing a manipulation can lead to code injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026

Pagina 2003 di 3155

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.