News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
37943 risultati
CVE ID :CVE-2026-42519 Published : April 29, 2026, 1:31 p.m. | 46 minutes ago Description :A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42520 Published : April 29, 2026, 1:31 p.m. | 46 minutes ago Description :Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Legacy Leak: Deprecated GNU C Library Functions Spark New Security Fears The GNU C Library (glibc), a cornerstone of the Linux ecosystem, has issued a security advisory. The disclosure highlights vulnerabilities in long-deprecated functions that, while no longer recommende ... Read more Published Date: Apr 29, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.
Kritiek beveiligingslek op GitHub.com gaf toegang tot miljoenen repositories Een kritieke kwetsbaarheid op GitHub.com maakte het mogelijk om toegang tot miljoenen publieke en private repositories te krijgen. Hetzelfde beveiligingslek maakte het ook mogelijk om in het geval van ... Read more Published Date: Apr 29, 2026 (22 hours, 56 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-3854
GitHub: Woah, a genuinely helpful AI-assisted bug report that isn't total slop. Here, Wiz, take this wad of cash Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub's git infrastructure that handed remote attackers full read/write access to private GitHub reposit ... Read more Published Date: Apr 29, 2026 (23 hours, 23 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-3854
Label Leak: Hardcoded Credentials in Snap One WattBox Devices Open Door to Root Access A critical vulnerability has been identified in the Snap One WattBox 800 and 820 series power controllers. The flaw, tracked as CVE-2026-41446 with a CVSS score of 9.2, reveals that diagnostic endpoin ... Read more Published Date: Apr 29, 2026 (23 hours, 37 minutes ago) Vulnerabilities has been mentioned in this article.
Cursor AI Coding Agent Vulnerability Allow Attackers to Execute Code on Developer’s Machine A high-severity vulnerability in Cursor, one of the most widely used AI-powered coding environments today, has put developers at direct risk of remote code execution. Tracked as CVE-2026-26268, the fl ... Read more Published Date: Apr 29, 2026 (23 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-26268
NVIDIA FLARE Alert: Critical SDK Vulnerabilities Open Doors to Full System Takeover NVIDIA has issued an urgent software update for the NVIDIA FLARE SDK, addressing multiple security vulnerabilities that could allow attackers to bypass authentication, execute malicious code, and tamp ... Read more Published Date: Apr 29, 2026 (22 hours, 24 minutes ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-42249 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derived from HTTP headers without validation. These values are passed directly to filepath.Join, allowing path traversal sequences (../) to be resolved and enabling files to be written outside the intended update staging directory. An attacker who can influence update responses can exploit this flaw to write arbitrary executables to attacker‑chosen locations accessible to the current user, including the Windows Startup directory. This allows execution of arbitrary executables. Critically, when chained with CVE‑2026‑42248 (Missing Signature Verification for Updates), an attacker can deliver malicious payloads that are written to sensitive locations and executed automatically. Because Ollama for Windows performs silent automatic updates and executes staged binaries without user interaction, this results in automatic and persistent code execution without user awareness. Maintainers of this project were notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Versions from 0.12.10 to 0.17.5 were tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42248 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature or trust validation is performed before staging or executing update payloads, enabling attacker‑supplied executables to be accepted and later executed by the application. Critically, Ollama for Windows performs silent automatic updates, so the malicious payload may be installed automatically without user awareness. Maintainers of this project were notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Versions from 0.12.10 to 0.17.5 were tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical zero-day vulnerability in Microsoft Windows. On April 28, 2026, the agency officially adde ... Read more Published Date: Apr 29, 2026 (22 hours, 49 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-32202
CVE ID :CVE-2026-22745 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2012 di 3162