Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37943 risultati

News
Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks

Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks A critical, currently unpatched remote code execution (RCE) vulnerability has been disclosed in LeRobot, Hugging Face’s popular open-source machine learning framework for real-world robotics. Tracked ... Read more Published Date: Apr 29, 2026 (22 hours, 52 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-25874

CVEfeed Newsroom29 apr 2026
VulnerabilitàAlta
CVE-2026-22741 - Static resource cache poisoning in Spring MVC and WebFlux

CVE ID :CVE-2026-22741 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients. Severity: 0.0 | NONE Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
News
Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks

Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks Google has released a critical security update for its Chrome desktop browser to address 30 security vulnerabilities, including four severe flaws that could enable Remote Code Execution (RCE) attacks. ... Read more Published Date: Apr 29, 2026 (21 hours, 3 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-7363 CVE-2026-7361 CVE-2026-7344 CVE-2026-7343 CVE-2026-7333

CVEfeed Newsroom29 apr 2026
VulnerabilitàAlta
CVE-2026-2902 - WP Meteor Website Speed Optimization Addon <= 3.4.16 - Unauthenticated Stored Cross-Site Scripting via Comment

CVE ID :CVE-2026-2902 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frontend_rewrite' function's 'WPMETEOR[N]WPMETEOR' placeholder content in all versions up to, and including, 3.4.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
News
Vulnerabilities in Ollama software

Vulnerabilities in Ollama software Vulnerabilities in Ollama software CVE ID CVE-2026-42248 Publication date 29 April 2026 Vendor Ollama Product Ollama Vulnerable versions From 0.12.10 through 0.17.5 Vulnerability type (CWE) Download o ... Read more Published Date: Apr 29, 2026 (21 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-42249 CVE-2026-42248

CVEfeed Newsroom29 apr 2026
VulnerabilitàAlta
CVE-2026-22740 - Spring Framework DoS with Multipart Temp Files in WebFlux

CVE ID :CVE-2026-22740 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected. Severity: 0.0 | NONE Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-42652 - WordPress User Registration plugin <= 5.1.5 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-42652 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-42642 - WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability

CVE ID :CVE-2026-42642 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-42644 - WordPress BetterDocs plugin <= 4.3.10 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-42644 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-42646 - WordPress TaxoPress plugin <= 3.44.0 - SQL Injection vulnerability

CVE ID :CVE-2026-42646 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n/a through Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-42641 - WordPress Share This Image plugin <= 2.14 - Server Side Request Forgery (SSRF) vulnerability

CVE ID :CVE-2026-42641 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-42645 - WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.11.0 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-42645 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026

Pagina 2013 di 3162

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.