Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37970 risultati

VulnerabilitàAlta
CVE-2026-40556 - Insecure Directory Permissions in GNU nano Leading to Privilege Abuse

CVE ID :CVE-2026-40556 Published : April 28, 2026, 3:16 p.m. | 3 hours ago Description :GNU nano creates the user’s ~/.local directory with overly permissive permissions when the directory does not exist yet. On first use of features requiring Cross-Desktop Group (XDG) data storage, nano explicitly requests directory mode 0777, making the directory world‑writable in environments where the process umask does not sufficiently restrict permissions. In systems with a relaxed or zero umask, such as container environments, CI/CD runners, embedded systems, or user shells configured with umask 000, this results in ~/.local being created as world‑writable. A local attacker can exploit a race window between nano’s creation of ~/.local and its subsequent creation of more restrictive subdirectories to write attacker‑controlled files into the victim’s XDG directory hierarchy. This problem was fixed in nano version 9.0 Severity: 2.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-27760 (CVSS 8.1)

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-27760 - OpenCATS PHP Code Injection via installer AJAX endpoint

CVE ID :CVE-2026-27760 Published : April 28, 2026, 3:16 p.m. | 3 hours ago Description :OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2025-67223 - Aranda Service Desk AFS File Disclosure

CVE ID :CVE-2025-67223 Published : April 28, 2026, 3:16 p.m. | 3 hours, 1 minute ago Description :The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7272 (CVSS 7.3)

A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can lead to path traversal. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-7272 - WilliamCloudQi matlab-mcp-server MCP index.ts execute_matlab_code path traversal

CVE ID :CVE-2026-7272 Published : April 28, 2026, 2:16 p.m. | 4 hours ago Description :A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can lead to path traversal. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
News
Vulnerability in GNU nano software

Vulnerability in GNU nano software Vulnerability in GNU nano software CVE ID CVE-2026-40556 Publication date 28 April 2026 Vendor GNU Product nano Vulnerable versions From 2.9.1 below 9.0 Vulnerability type (CWE) Incorrect Permission A ... Read more Published Date: Apr 28, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-40556

CVEfeed Newsroom28 apr 2026
VulnerabilitàAlta
CVE-2026-7271 - DV0x creative-ad-agent creative-ad-agent-server sdk-server.ts path traversal

CVE ID :CVE-2026-7271 Published : April 28, 2026, 1:19 p.m. | 2 hours, 57 minutes ago Description :A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file server/sdk-server.ts of the component creative-ad-agent-server. Performing a manipulation of the argument req.params results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The patch is named 3d255865a957f3740b8724dd914502c0f44d4970. Applying a patch is the recommended action to fix this issue. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7309 - Openshift-controller-manager: openshift container platform: information disclosure via environment variable injection

CVE ID :CVE-2026-7309 Published : April 28, 2026, 1:19 p.m. | 2 hours, 57 minutes ago Description :A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantiate` API. This incomplete fix for a previous vulnerability allows for information disclosure, specifically impacting the confidentiality of build traffic. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7269 - SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting

CVE ID :CVE-2026-7269 Published : April 28, 2026, 1:19 p.m. | 2 hours, 57 minutes ago Description :A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /index.php?page=product. Performing a manipulation of the argument ID results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-5435 - Potential buffer overflow in ns_sprintrrf TSIG handling path

CVE ID :CVE-2026-5435 Published : April 28, 2026, 1:19 p.m. | 57 minutes ago Description :The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-5779 - Multiple vulnerabilities in MphRx's Minerva

CVE ID :CVE-2026-5779 Published : April 28, 2026, 1:19 p.m. | 57 minutes ago Description :An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the information of other registered users. Successful exploitation of this vulnerability allows an authenticated user to modify other users' information, such as their email address, and request a new password via the '/webconnect/#/forgotPassword' endpoint. This could lead to complete account takeover. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026

Pagina 2027 di 3165

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.