Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37943 risultati

VulnerabilitàAlta
CVE-2025-10503 - Reflected Cross-Site Scripting via Authentication Endpoint in WSO2 Identity Server

CVE ID :CVE-2025-10503 Published : April 29, 2026, 9:16 a.m. | 3 hours, 1 minute ago Description :The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting. An attacker can leverage this vulnerability to redirect the user's browser to a malicious website, modify the user interface of the web page, retrieve information from the browser, or cause other harmful actions. However, due to the protection of session-related cookies with the httpOnly flag, session hijacking is not possible. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
News
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (K ... Read more Published Date: Apr 29, 2026 (23 hours, 39 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-32202 CVE-2026-34197 CVE-2026-33032 CVE-2026-21513 CVE-2026-21510 CVE-2024-1709 CVE-2024-1708

CVEfeed Newsroom29 apr 2026
VulnerabilitàAlta
CVE-2026-42377 - WordPress SureForms Pro plugin <= 2.8.0 - Broken Access Control vulnerability

CVE ID :CVE-2026-42377 Published : April 29, 2026, 8:16 a.m. | 4 hours, 1 minute ago Description :Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
News
LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure

LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI's LiteLLM Python package has come under active exploitation ... Read more Published Date: Apr 29, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom29 apr 2026
VulnerabilitàAlta
CVE-2026-35155 - Dell iDRAC10 Insufficiently Protected Credentials and Race Condition Vulnerability

CVE ID :CVE-2026-35155 Published : April 29, 2026, 5:16 a.m. | 5 hours, 1 minute ago Description :Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-21023 - Android PackageManagerService Data Authenticity Verification Bypass

CVE ID :CVE-2026-21023 Published : April 29, 2026, 5:16 a.m. | 5 hours, 1 minute ago Description :Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-23773 - Dell Disk Library for Mainframe SSRF

CVE ID :CVE-2026-23773 Published : April 29, 2026, 4:16 a.m. | 6 hours, 1 minute ago Description :Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-42615 - GCHQ CyberChef XSS Vulnerability

CVE ID :CVE-2026-42615 Published : April 29, 2026, 4:16 a.m. | 6 hours, 1 minute ago Description :GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
News
CISA adds Two vulnerabilities to KEV catalog

CISA adds Two vulnerabilities to KEV catalog April 29, 2026CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation — CVE-2024-1708, a ConnectWise ScreenConnect path traversal vul ... Read more Published Date: Apr 29, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32202 CVE-2024-1709 CVE-2024-1708

CVEfeed Newsroom29 apr 2026
News
Checkmarx Falls Victim to Credential Harvesting Attack

Checkmarx Falls Victim to Credential Harvesting Attack Checkmarx, a global leader in application security testing, has disclosed a significant breach of its internal systems. The attack originated not from a direct assault, but through a sophisticated sup ... Read more Published Date: Apr 29, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom29 apr 2026
News
CISA Sounds the Alarm: State-Sponsored Hackers Weaponize New Windows and ScreenConnect Flaws

CISA Sounds the Alarm: State-Sponsored Hackers Weaponize New Windows and ScreenConnect Flaws The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog, adding two high-stakes flaws that are currently being weaponized by state-sp ... Read more Published Date: Apr 29, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom29 apr 2026
News
Chrome Security Alert: Google Patches 30 Vulnerabilities in Massive Desktop Update

Chrome Security Alert: Google Patches 30 Vulnerabilities in Massive Desktop Update Google has released a significant security update for the Chrome stable channel, addressing 30 security fixes. The update, which brings the browser to version 147.0.7727.137/138 for Windows and Mac an ... Read more Published Date: Apr 29, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom29 apr 2026

Pagina 2015 di 3162

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.