Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38015 risultati

VulnerabilitàCritica
CVE-2026-7240 (CVSS 9.8)

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument User leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-7237 (CVSS 7.3)

A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality of the file packages/scaffold-mcp/src/server/index.ts of the component write-to-file Tool. The manipulation of the argument file_path results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 1.1.0 can resolve this issue. The patch is identified as c4d23592ae5fb59cfeefc4641e6826f8ac89b9c6. You should upgrade the affected component.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-7237 - AgiFlow scaffold-mcp write-to-file Tool index.ts path traversal

CVE ID :CVE-2026-7237 Published : April 28, 2026, 8:16 a.m. | 2 hours ago Description :A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality of the file packages/scaffold-mcp/src/server/index.ts of the component write-to-file Tool. The manipulation of the argument file_path results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 1.1.0 can resolve this issue. The patch is identified as c4d23592ae5fb59cfeefc4641e6826f8ac89b9c6. You should upgrade the affected component. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7240 - Totolink A8000RU CGI cstecgi.cgi setVpnAccountCfg os command injection

CVE ID :CVE-2026-7240 Published : April 28, 2026, 8:16 a.m. | 2 hours ago Description :A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument User leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7234 (CVSS 7.3)

A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of the argument request.url can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-7233 - Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds

CVE ID :CVE-2026-7233 Published : April 28, 2026, 7:16 a.m. | 1 hour ago Description :A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7234 - BrowserOperator browser-operator-core server.js startsWith path traversal

CVE ID :CVE-2026-7234 Published : April 28, 2026, 7:16 a.m. | 1 hour ago Description :A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of the argument request.url can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7229 - code-projects Coaching Management System POST reply.php sql injection

CVE ID :CVE-2026-7229 Published : April 28, 2026, 7:16 a.m. | 1 hour ago Description :A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing a manipulation of the argument complaintreply results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-40356 - Kerberos 5 Integer Underflow Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-40356 Published : April 28, 2026, 7:16 a.m. | 1 hour ago Description :In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-40967 - Spring AI Unvalidated Filter Expression Converter Vulnerability (Code Injection)

CVE ID :CVE-2026-40967 Published : April 28, 2026, 7:16 a.m. | 1 hour ago Description :In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-5306 - Check & Log Email < 2.0.13 - Unauthenticated Stored XSS

CVE ID :CVE-2026-5306 Published : April 28, 2026, 7:16 a.m. | 1 hour ago Description :The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7230 - SourceCodester Safety Anger Pad cross site scripting

CVE ID :CVE-2026-7230 Published : April 28, 2026, 7:16 a.m. | 1 hour ago Description :A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manipulation of the argument angerDisplay results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026

Pagina 2036 di 3168

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.