Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38015 risultati

VulnerabilitàAlta
CVE-2026-41636 - Apache Thrift: Node.js skip() recursion

CVE ID :CVE-2026-41636 Published : April 28, 2026, 10:16 a.m. | 4 hours ago Description :Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41607 - Apache Thrift: C++ JSON OOB read

CVE ID :CVE-2026-41607 Published : April 28, 2026, 10:16 a.m. | 4 hours ago Description :Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41606 - Apache Thrift: c_glib dispatch stack overflow

CVE ID :CVE-2026-41606 Published : April 28, 2026, 10:16 a.m. | 4 hours ago Description :Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41605 - Apache Thrift: Swift Compact Protocol integer overflow

CVE ID :CVE-2026-41605 Published : April 28, 2026, 10:16 a.m. | 2 hours ago Description :Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41604 - Apache Thrift: Swift Range crash in skip()

CVE ID :CVE-2026-41604 Published : April 28, 2026, 10:16 a.m. | 2 hours ago Description :Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41603 - Apache Thrift: Java TSSLTransportFactory hostname verification

CVE ID :CVE-2026-41603 Published : April 28, 2026, 10:16 a.m. | 2 hours ago Description :Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-41602 - Apache Thrift: Go TFramedTransport uint32 overflow

CVE ID :CVE-2026-41602 Published : April 28, 2026, 10:16 a.m. | 2 hours ago Description :Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàCritica
CVE-2026-7248 (CVSS 9.8)

A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-7247 (CVSS 7.2)

A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-7248 - D-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow

CVE ID :CVE-2026-7248 Published : April 28, 2026, 9:16 a.m. | 3 hours ago Description :A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7247 - D-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow

CVE ID :CVE-2026-7247 Published : April 28, 2026, 9:16 a.m. | 3 hours ago Description :A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàCritica
CVE-2026-7244 (CVSS 9.8)

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)28 apr 2026

Pagina 2034 di 3168

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.