Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38053 risultati

VulnerabilitàAlta
CVE-2026-7097 (CVSS 8.8)

A weakness has been identified in Tenda F456 1.0.0.5. This issue affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

NVD (NIST)27 apr 2026
VulnerabilitàAlta
CVE-2026-7096 (CVSS 8.8)

A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_loid results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)27 apr 2026
VulnerabilitàAlta
CVE-2026-7097 - Tenda F456 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow

CVE ID :CVE-2026-7097 Published : April 27, 2026, 8:16 a.m. | 1 hour, 59 minutes ago Description :A weakness has been identified in Tenda F456 1.0.0.5. This issue affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7096 - Tenda HG3 formgponConf os command injection

CVE ID :CVE-2026-7096 Published : April 27, 2026, 8:16 a.m. | 1 hour, 59 minutes ago Description :A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_loid results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
News
Critical 9.8 CVSS RCE Hijacks Pipecat Voice Agents

Critical 9.8 CVSS RCE Hijacks Pipecat Voice Agents A critical vulnerability has been disclosed in Pipecat, the popular open-source Python framework used to build voice and conversational agents. The flaw, designated as CVE-2025-62373, carries a devast ... Read more Published Date: Apr 27, 2026 (1 day, 16 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom27 apr 2026
News
CrowdStrike en Tenable verhelpen ernstige kwetsbaarheden

CrowdStrike en Tenable verhelpen ernstige kwetsbaarheden CrowdStrike en Tenable hebben kritieke kwetsbaarheden in hun producten gedicht. In het geval van CrowdStrike gaat het om een path traversal-kwetsbaarheid (CVE-2026-40050) in LogScale. LogScale is een ... Read more Published Date: Apr 27, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33694 CVE-2026-40050

CVEfeed Newsroom27 apr 2026
VulnerabilitàAlta
CVE-2026-7094 (CVSS 7.3)

A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the component puppeteer_navigate. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)27 apr 2026
VulnerabilitàAlta
CVE-2026-7092 - code-projects Invoice System in Laravel Profile profile improper authorization

CVE ID :CVE-2026-7092 Published : April 27, 2026, 7:16 a.m. | 59 minutes ago Description :A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile Handler. Such manipulation of the argument ID leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7091 - code-projects Invoice System in Laravel User Management user improper authorization

CVE ID :CVE-2026-7091 Published : April 27, 2026, 7:16 a.m. | 59 minutes ago Description :A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User Management Handler. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-42371 - Uriparser Numeric Truncation Vulnerability

CVE ID :CVE-2026-42371 Published : April 27, 2026, 7:16 a.m. | 59 minutes ago Description :uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7093 - code-projects Invoice System in Laravel Invoice Endpoint invoice improper authorization

CVE ID :CVE-2026-7093 Published : April 27, 2026, 7:16 a.m. | 59 minutes ago Description :A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-3008 - Vulnerability in Notepad++

CVE ID :CVE-2026-3008 Published : April 27, 2026, 7:16 a.m. | 59 minutes ago Description :Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026

Pagina 2062 di 3172

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.