Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38053 risultati

VulnerabilitàAlta
CVE-2026-5937 - Foxit PDF Editor/Reader's insufficient parameter validation leads to denial-of-service vulnerability

CVE ID :CVE-2026-5937 Published : April 27, 2026, 11 a.m. | 1 hour, 14 minutes ago Description :Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-5938 - Foxit PDF Editor/Reader Infinite Loop Denial-of-Service Vulnerability

CVE ID :CVE-2026-5938 Published : April 27, 2026, 11 a.m. | 1 hour, 14 minutes ago Description :Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-5940 - Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability

CVE ID :CVE-2026-5940 Published : April 27, 2026, 12:16 p.m. | 1 hour, 59 minutes ago Description :Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-5942 - Foxit PDF Editor/Reader AcroForm Signature Use-After-Free Vulnerability

CVE ID :CVE-2026-5942 Published : April 27, 2026, 12:16 p.m. | 1 hour, 59 minutes ago Description :Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-5943 - Foxit PDF Editor/Reader AcroForm Annotation Use-After-Free Remote Code Execution Vulnerability

CVE ID :CVE-2026-5943 Published : April 27, 2026, 12:16 p.m. | 1 hour, 59 minutes ago Description :Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-5939 - UAF in Foxit PDF Editor/Reader via XFA calculate event

CVE ID :CVE-2026-5939 Published : April 27, 2026, 12:16 p.m. | 1 hour, 59 minutes ago Description :A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-5941 - Foxit PDF Editor/Reader AcroForm Signature Remote Code Execution Vulnerability

CVE ID :CVE-2026-5941 Published : April 27, 2026, 12:16 p.m. | 1 hour, 59 minutes ago Description :Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7117 - code-projects Employee Management System approve.php sql injection

CVE ID :CVE-2026-7117 Published : April 27, 2026, 12:16 p.m. | 1 hour, 59 minutes ago Description :A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the argument id/token can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7116 - code-projects Employee Management System mark.php cross site scripting

CVE ID :CVE-2026-7116 Published : April 27, 2026, 12:16 p.m. | 1 hour, 59 minutes ago Description :A security flaw has been discovered in code-projects Employee Management System 1.0. This issue affects some unknown processing of the file 370project/mark.php. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-42410 - WordPress TheGem theme Elements (for Elementor) plugin < 5.12.1.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-42410 Published : April 27, 2026, 10:41 a.m. | 1 hour, 34 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows DOM-Based XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7112 - NousResearch hermes-agent API_SERVER_KEY api_server.py _check_auth improper authentication

CVE ID :CVE-2026-7112 Published : April 27, 2026, 10:16 a.m. | 1 hour, 59 minutes ago Description :A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY Handler. The manipulation leads to improper authentication. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-33454 - Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)

CVE ID :CVE-2026-33454 Published : April 27, 2026, 9:42 a.m. | 32 minutes ago Description :The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via setInFilterStartsWith. As a result, when a Camel application consumes mail through camel-mail (for example via from(\"imap://...\") or from(\"pop3://...\")) the inbound filter check is skipped and Camel-prefixed MIME headers are mapped unfiltered into the Exchange. An attacker who can deliver an email to a mailbox monitored by such a consumer can inject Camel-specific headers that, for some Camel components downstream of the mail consumer (such as camel-bean, camel-exec, or camel-sql), can alter the behaviour of the route. This is the same pattern that was previously addressed in camel-undertow (CVE-2025-30177) and the broader incoming-header filter (CVE-2025-27636 and CVE-2025-29891). This issue affects Apache Camel: from 3.0.0 before 4.14.6, from 4.15.0 before 4.18.1. Users are recommended to upgrade to version 4.19.0, which fixes the issue. If users are on the 4.18.x LTS releases stream, then they are suggested to upgrade to 4.18.1. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026

Pagina 2059 di 3172

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.