News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
37943 risultati
CVE ID :CVE-2025-10503 Published : April 29, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting. An attacker can leverage this vulnerability to redirect the user's browser to a malicious website, modify the user interface of the web page, retrieve information from the browser, or cause other harmful actions. However, due to the protection of session-related cookies with the httpOnly flag, session hijacking is not possible. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (K ... Read more Published Date: Apr 29, 2026 (23 hours, 39 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-32202 CVE-2026-34197 CVE-2026-33032 CVE-2026-21513 CVE-2026-21510 CVE-2024-1709 CVE-2024-1708
CVE ID :CVE-2026-42377 Published : April 29, 2026, 8:16 a.m. | 4 hours, 1 minute ago Description :Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI's LiteLLM Python package has come under active exploitation ... Read more Published Date: Apr 29, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-35155 Published : April 29, 2026, 5:16 a.m. | 5 hours, 1 minute ago Description :Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21023 Published : April 29, 2026, 5:16 a.m. | 5 hours, 1 minute ago Description :Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-23773 Published : April 29, 2026, 4:16 a.m. | 6 hours, 1 minute ago Description :Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42615 Published : April 29, 2026, 4:16 a.m. | 6 hours, 1 minute ago Description :GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA adds Two vulnerabilities to KEV catalog April 29, 2026CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation — CVE-2024-1708, a ConnectWise ScreenConnect path traversal vul ... Read more Published Date: Apr 29, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32202 CVE-2024-1709 CVE-2024-1708
Checkmarx Falls Victim to Credential Harvesting Attack Checkmarx, a global leader in application security testing, has disclosed a significant breach of its internal systems. The attack originated not from a direct assault, but through a sophisticated sup ... Read more Published Date: Apr 29, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.
CISA Sounds the Alarm: State-Sponsored Hackers Weaponize New Windows and ScreenConnect Flaws The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog, adding two high-stakes flaws that are currently being weaponized by state-sp ... Read more Published Date: Apr 29, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.
Chrome Security Alert: Google Patches 30 Vulnerabilities in Massive Desktop Update Google has released a significant security update for the Chrome stable channel, addressing 30 security fixes. The update, which brings the browser to version 147.0.7727.137/138 for Windows and Mac an ... Read more Published Date: Apr 29, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.
Pagina 2015 di 3162