News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38037 risultati
CVE ID :CVE-2026-32644 Published : April 28, 2026, 1:16 a.m. | 3 hours ago Description :Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-32649 Published : April 28, 2026, 1:16 a.m. | 3 hours ago Description :A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-20766 Published : April 28, 2026, 1:16 a.m. | 3 hours ago Description :An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
FIRESTARTER: Cisco ASA Backdoor The Advisory That Changes EverythingOn April 23, 2026, CISA and the United Kingdom National Cyber Security Centre jointly assessed that FIRESTARTER — a backdoor that allows remote access and control — ... Read more Published Date: Apr 28, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-20362 CVE-2025-20333
Unfiltered: The 9.8 CVSS Deserialization Loophole Hijacking Apache MINA Apache MINA is a workhorse for development teams building high-performance, scalable network applications. By providing an abstract, event-driven asynchronous API over transports like TCP/IP and UDP/I ... Read more Published Date: Apr 28, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.
CVE ID :CVE-2026-7196 Published : April 28, 2026, 12:16 a.m. | 1 hour, 59 minutes ago Description :A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument deleteid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7199 Published : April 28, 2026, 12:16 a.m. | 3 hours, 59 minutes ago Description :A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41371 Published : April 28, 2026, 12:16 a.m. | 1 hour, 59 minutes ago Description :OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host.
CVE ID :CVE-2026-41364 Published : April 28, 2026, 12:16 a.m. | 1 hour, 59 minutes ago Description :OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2044 di 3170