News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
37943 risultati
Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks A critical, currently unpatched remote code execution (RCE) vulnerability has been disclosed in LeRobot, Hugging Face’s popular open-source machine learning framework for real-world robotics. Tracked ... Read more Published Date: Apr 29, 2026 (22 hours, 52 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-25874
CVE ID :CVE-2026-22741 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients. Severity: 0.0 | NONE Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks Google has released a critical security update for its Chrome desktop browser to address 30 security vulnerabilities, including four severe flaws that could enable Remote Code Execution (RCE) attacks. ... Read more Published Date: Apr 29, 2026 (21 hours, 3 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-7363 CVE-2026-7361 CVE-2026-7344 CVE-2026-7343 CVE-2026-7333
CVE ID :CVE-2026-2902 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frontend_rewrite' function's 'WPMETEOR[N]WPMETEOR' placeholder content in all versions up to, and including, 3.4.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities in Ollama software Vulnerabilities in Ollama software CVE ID CVE-2026-42248 Publication date 29 April 2026 Vendor Ollama Product Ollama Vulnerable versions From 0.12.10 through 0.17.5 Vulnerability type (CWE) Download o ... Read more Published Date: Apr 29, 2026 (21 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-42249 CVE-2026-42248
CVE ID :CVE-2026-22740 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected. Severity: 0.0 | NONE Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42652 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42642 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42644 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42646 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n/a through Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42641 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42645 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2013 di 3162