Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37970 risultati

VulnerabilitàAlta
CVE-2026-41379 (CVSS 7.1)

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Talk Voice configuration persistence. Attackers with operator.write privileges can exploit the chat.send endpoint to reach and modify sensitive voice configuration settings intended for administrators only.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-41378 (CVSS 8.8)

OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.request dispatch to achieve remote code execution on the gateway.

NVD (NIST)28 apr 2026
News
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push

Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push Cybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to obtain remote code exe ... Read more Published Date: Apr 28, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197 CVE-2026-33032 CVE-2026-3854

CVEfeed Newsroom28 apr 2026
News
Critical GitHub.com and Enterprise Server RCE Vulnerability Enables Full Server Compromise

Critical GitHub.com and Enterprise Server RCE Vulnerability Enables Full Server Compromise A critical remote code execution (RCE) vulnerability tracked as CVE-2026-3854 in GitHub’s internal git infrastructure that could have allowed any authenticated user to compromise backend servers, acce ... Read more Published Date: Apr 28, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-3854

CVEfeed Newsroom28 apr 2026
News
Microsoft Confirms Remote Desktop Warnings May Display Incorrectly After April Update

Microsoft Confirms Remote Desktop Warnings May Display Incorrectly After April Update Microsoft has officially acknowledged a known issue in its April 2026 Windows 11 cumulative update: Remote Desktop Protocol (RDP) security warning dialogs may render incorrectly on certain system conf ... Read more Published Date: Apr 28, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-26151

CVEfeed Newsroom28 apr 2026
VulnerabilitàAlta
CVE-2026-38948 - FUEL CMS SVG Upload XSS

CVE ID :CVE-2026-38948 Published : April 28, 2026, 4:16 p.m. | 2 hours ago Description :Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-38651 - Netmaker JWT Authentication Bypass Vulnerability

CVE ID :CVE-2026-38651 Published : April 28, 2026, 4:16 p.m. | 2 hours ago Description :Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2025-60889 - StellarGroup HPX Deserialization Code Execution Vulnerability

CVE ID :CVE-2025-60889 Published : April 28, 2026, 4:16 p.m. | 2 hours, 1 minute ago Description :Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2025-60887 - Cista Insecure Deserialization of Untrusted Input

CVE ID :CVE-2025-60887 Published : April 28, 2026, 4:16 p.m. | 2 hours, 1 minute ago Description :An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Classes with pointer-like mechanics under the cista::raw namespace are prone to reference tampering, where Cista does not perform sufficient checks to safeguard against self-referencing pointers and referencing other data within the payload. The leak occurs if the deserialized values are observable by the attacker. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
News
Critical LiteLLM SQL Injection Vulnerability Exploited in the Wild

Critical LiteLLM SQL Injection Vulnerability Exploited in the Wild A critical pre-authentication SQL injection vulnerability in LiteLLM, a widely used open-source AI gateway with over 22,000 GitHub stars, is actively being exploited in the wild. Tracked as CVE-2026-4 ... Read more Published Date: Apr 28, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom28 apr 2026
VulnerabilitàAlta
CVE-2026-41873 - Pony Mail: Admin account takeover via request smuggling

CVE ID :CVE-2026-41873 Published : April 28, 2026, 4:16 p.m. | 2 hours ago Description :** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under development under the name "Pony Mail Foal" that is not affected by this issue, but hasn't been released yet. As the Lua implementation of this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7289 (CVSS 8.8)

A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

NVD (NIST)28 apr 2026

Pagina 2025 di 3165

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.