Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38099 risultati

VulnerabilitàAlta
CVE-2026-6996 - BDCOM P3310D rmon event Tab cross site scripting

CVE ID :CVE-2026-6996 Published : April 25, 2026, 8:16 p.m. | 11 hours, 58 minutes ago Description :A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6994 - Envoy Query Parameter header_mutation.cc params.add injection

CVE ID :CVE-2026-6994 Published : April 25, 2026, 7:16 p.m. | 10 hours, 58 minutes ago Description :A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes injection. Remote exploitation of the attack is possible. Patch name: f8f4f1e02fdc64ecd4acf2d903208dd7285ad3a4. It is suggested to install a patch to address this issue. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6993 - go-kratos http.DefaultServeMux Fallback server.go NewServer confused deputy

CVE ID :CVE-2026-6993 Published : April 25, 2026, 7:16 p.m. | 10 hours, 58 minutes ago Description :A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 0284a5bcf92b5a7ee015300ce3051baf7ae4718d. Applying a patch is advised to resolve this issue. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6995 - BDCOM P3310D New User index.asp cross site scripting

CVE ID :CVE-2026-6995 Published : April 25, 2026, 8:16 p.m. | 11 hours, 58 minutes ago Description :A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipulation of the argument User name results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6992 (CVSS 7.2)

A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. The manipulation of the argument pin leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)25 apr 2026
VulnerabilitàAlta
CVE-2026-6992 - Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection

CVE ID :CVE-2026-6992 Published : April 25, 2026, 6:16 p.m. | 11 hours, 58 minutes ago Description :A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. The manipulation of the argument pin leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6988 (CVSS 8.8)

A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon. This issue affects the function formRoute of the file /boaform/formRouting of the component Boa Service. This manipulation of the argument nextHop causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.

NVD (NIST)25 apr 2026
VulnerabilitàAlta
CVE-2026-6988 - Tenda HG10 Boa Service formRouting formRoute buffer overflow

CVE ID :CVE-2026-6988 Published : April 25, 2026, 6:16 p.m. | 9 hours, 58 minutes ago Description :A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon. This issue affects the function formRoute of the file /boaform/formRouting of the component Boa Service. This manipulation of the argument nextHop causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6991 - colinhacks Zod CUID Data Type regexes.ts sql injection

CVE ID :CVE-2026-6991 Published : April 25, 2026, 6:16 p.m. | 11 hours, 58 minutes ago Description :A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6990 - projeto-siga novo cross site scripting

CVE ID :CVE-2026-6990 Published : April 25, 2026, 6:16 p.m. | 11 hours, 58 minutes ago Description :A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of the argument Nome/Descrição results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
News
CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack

CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding two actively exploited vulnerabilities in SimpleHelp remote support software. Remote access tools are ... Read more Published Date: Apr 25, 2026 (2 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-57728 CVE-2024-57726

CVEfeed Newsroom25 apr 2026
VulnerabilitàAlta
CVE-2026-6987 (CVSS 7.3)

A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)25 apr 2026

Pagina 2080 di 3175

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.