Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38099 risultati

VulnerabilitàAlta
CVE-2026-7054 - Tenda F456 httpd PPTPDClient fromPptpUserAdd buffer overflow

CVE ID :CVE-2026-7054 Published : April 26, 2026, 10:17 p.m. | 1 hour, 57 minutes ago Description :A weakness has been identified in Tenda F456 1.0.0.5. This vulnerability affects the function fromPptpUserAdd of the file /goform/PPTPDClient of the component httpd. Executing a manipulation of the argument opttype/usernamewith can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-7053 - Tenda F456 httpd L7Prot frmL7ProtForm buffer overflow

CVE ID :CVE-2026-7053 Published : April 26, 2026, 10:17 p.m. | 1 hour, 57 minutes ago Description :A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-7045 - baomidou dynamic-datasource StandardEvaluationContext/SpelExpressionParser DsSpelExpressionProcessor.java DsSpelExpressionProcessor#doDetermineDatasource injection

CVE ID :CVE-2026-7045 Published : April 26, 2026, 10:17 p.m. | 1 hour, 57 minutes ago Description :A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the component StandardEvaluationContext/SpelExpressionParser. This manipulation causes injection. The attack may be initiated remotely. Patch name: 273fcedaee984c08197c0890f14190b86ab7e0b8. It is recommended to apply a patch to fix this issue. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-7044 - GreenCMS index.php themeadd unrestricted upload

CVE ID :CVE-2026-7044 Published : April 26, 2026, 10:17 p.m. | 1 hour, 57 minutes ago Description :A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2018-25297 - Wansview 1.0.2 Denial of Service via Buffer Overflow

CVE ID :CVE-2018-25297 Published : April 26, 2026, 10:17 p.m. | 1 hour, 57 minutes ago Description :Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can inject 2000-byte payloads into the Camera name and DID number fields during camera addition to trigger application crashes. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2018-25296 - P10 Central Management Software 1.4.13 Denial of Service

CVE ID :CVE-2018-25296 Published : April 26, 2026, 1:19 p.m. | 8 hours, 55 minutes ago Description :P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 2000-byte payload into the password field and click login to trigger an application crash and denial of service. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2018-25295 - ObserverIP Scan Tool 1.4.0.1 Denial of Service via IP Field

CVE ID :CVE-2018-25295 Published : April 26, 2026, 1:19 p.m. | 8 hours, 55 minutes ago Description :ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the IP input field. Attackers can paste a 2000-byte buffer of repeated characters into the IP field and trigger a search operation to cause an application crash. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2018-25294 - CEWE Photoshow 6.3.4 Buffer Overflow Denial of Service

CVE ID :CVE-2018-25294 Published : April 26, 2026, 1:19 p.m. | 6 hours, 55 minutes ago Description :CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2018-25293 - Prime95 29.4b7 Denial of Service via Proxy Password Field

CVE ID :CVE-2018-25293 Published : April 26, 2026, 1:19 p.m. | 8 hours, 55 minutes ago Description :Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to crash the application by supplying an excessively long string in the optional proxy password field. Attackers can trigger a denial of service by entering a 6000-byte payload into the proxy password parameter, causing the application to crash when processing the connection settings. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2018-25292 - Bome Restorator 1793 Denial of Service via Buffer Overflow

CVE ID :CVE-2018-25292 Published : April 26, 2026, 1:19 p.m. | 8 hours, 55 minutes ago Description :Bome Restorator 1793 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can create a malicious payload exceeding 4000 bytes and paste it into the Name input field to trigger an application crash and denial of service. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2018-25290 - Easyboot 6.6.0 Buffer Overflow Denial of Service

CVE ID :CVE-2018-25290 Published : April 26, 2026, 1:19 p.m. | 8 hours, 55 minutes ago Description :Easyboot 6.6.0 contains a buffer overflow vulnerability in the Replace Text function that allows local attackers to crash the application by supplying an oversized string. Attackers can trigger the vulnerability by accessing File > Tools > Replace Text and pasting a 7000-byte payload into the text fields to cause a denial of service. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2018-25291 - Project64 2.3.2 Denial of Service via Plugin Directory

CVE ID :CVE-2018-25291 Published : April 26, 2026, 1:19 p.m. | 8 hours, 55 minutes ago Description :Project64 2.3.2 contains a buffer overflow vulnerability in the Plugin Directory settings field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 6000-byte payload into the Plugin Directory field through the Options > Settings > Directories interface to trigger an application crash when settings are reopened. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026

Pagina 2074 di 3175

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.