Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37970 risultati

VulnerabilitàAlta
CVE-2026-7280 - eMPIA Technology|AVACAST - Unquoted Service Path

CVE ID :CVE-2026-7280 Published : April 28, 2026, 10:16 a.m. | 4 hours ago Description :AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7264 - SourceCodester Pizzafy Ecommerce System ajax.php get_cart_items sql injection

CVE ID :CVE-2026-7264 Published : April 28, 2026, 10:16 a.m. | 4 hours ago Description :A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items of the file /admin/ajax.php?action=get_cart_items. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
News
Apache Camel Under Fire: Multiple RCE Flaws Expose Critical Integration Infrastructure

Apache Camel Under Fire: Multiple RCE Flaws Expose Critical Integration Infrastructure Apache Camel, the ubiquitous open-source integration framework used to connect disparate data systems, is facing a significant security challenge. Researchers have identified a series of critical vuln ... Read more Published Date: Apr 28, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom28 apr 2026
VulnerabilitàAlta
CVE-2026-41636 - Apache Thrift: Node.js skip() recursion

CVE ID :CVE-2026-41636 Published : April 28, 2026, 10:16 a.m. | 4 hours ago Description :Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41607 - Apache Thrift: C++ JSON OOB read

CVE ID :CVE-2026-41607 Published : April 28, 2026, 10:16 a.m. | 4 hours ago Description :Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41606 - Apache Thrift: c_glib dispatch stack overflow

CVE ID :CVE-2026-41606 Published : April 28, 2026, 10:16 a.m. | 4 hours ago Description :Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41605 - Apache Thrift: Swift Compact Protocol integer overflow

CVE ID :CVE-2026-41605 Published : April 28, 2026, 10:16 a.m. | 2 hours ago Description :Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41604 - Apache Thrift: Swift Range crash in skip()

CVE ID :CVE-2026-41604 Published : April 28, 2026, 10:16 a.m. | 2 hours ago Description :Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41603 - Apache Thrift: Java TSSLTransportFactory hostname verification

CVE ID :CVE-2026-41603 Published : April 28, 2026, 10:16 a.m. | 2 hours ago Description :Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41602 - Apache Thrift: Go TFramedTransport uint32 overflow

CVE ID :CVE-2026-41602 Published : April 28, 2026, 10:16 a.m. | 2 hours ago Description :Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàCritica
CVE-2026-7248 (CVSS 9.8)

A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-7247 (CVSS 7.2)

A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

NVD (NIST)28 apr 2026

Pagina 2030 di 3165

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.