Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38099 risultati

VulnerabilitàAlta
CVE-2026-6985 - Cesanta Mongoose TCP Option net_builtin.c handle_opt infinite loop

CVE ID :CVE-2026-6985 Published : April 25, 2026, 5:16 p.m. | 10 hours, 58 minutes ago Description :A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handler. This manipulation of the argument optlen causes infinite loop. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.21 is able to resolve this issue. Upgrading the affected component is advised. VulDB has contacted the vendor early and they confirmed quickly, that this issue got fixed already. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6987 - PicoClaw Web Launcher Management Plane restart command injection

CVE ID :CVE-2026-6987 Published : April 25, 2026, 5:16 p.m. | 10 hours, 58 minutes ago Description :A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6986 - Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification

CVE ID :CVE-2026-6986 Published : April 25, 2026, 5:16 p.m. | 10 hours, 58 minutes ago Description :A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic signature. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 7.21 is capable of addressing this issue. It is advisable to upgrade the affected component. VulDB has contacted the vendor early and they confirmed quickly, that this issue got fixed already. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6989 - Tenda F453 Telnet Service telnet TendaTelnet command injection

CVE ID :CVE-2026-6989 Published : April 25, 2026, 6:16 p.m. | 11 hours, 58 minutes ago Description :A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6984 - AstrBotDevs AstrBot Dashboard API t2i.py create_template special elements used in a template engine

CVE ID :CVE-2026-6984 Published : April 25, 2026, 4:16 p.m. | 11 hours, 58 minutes ago Description :A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The manipulation results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6982 - star7th ShowDoc API Page Sort Endpoint PageController.class.PHP sql injection

CVE ID :CVE-2026-6982 Published : April 25, 2026, 3:16 p.m. | 10 hours, 58 minutes ago Description :A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/Api/Controller/PageController.class.PHP of the component API Page Sort Endpoint. Executing a manipulation of the argument pages can lead to sql injection. The attack may be launched remotely. Upgrading to version 3.8.1 addresses this issue. It is suggested to upgrade the affected component. According to the researcher, "[t]he vendor explicitly stated they will not backport patches to the older affected versions." Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6981 - IhateCreatingUserNames2 AiraHub2 Endpoint AiraHub.py sync_agents server-side request forgery

CVE ID :CVE-2026-6981 Published : April 25, 2026, 3:16 p.m. | 10 hours, 58 minutes ago Description :A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of the component Endpoint. Performing a manipulation results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6983 - pagekit download server-side request forgery

CVE ID :CVE-2026-6983 Published : April 25, 2026, 4:16 p.m. | 9 hours, 58 minutes ago Description :A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6980 (CVSS 7.3)

A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd. This impacts the function repo_path of the file main.py. Such manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)25 apr 2026
VulnerabilitàAlta
CVE-2026-6980 - Divyanshu-hash GitPilot-MCP main.py repo_path command injection

CVE ID :CVE-2026-6980 Published : April 25, 2026, 2:16 p.m. | 11 hours, 58 minutes ago Description :A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd. This impacts the function repo_path of the file main.py. Such manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6979 - devlikeapro WAHA API Request media.controller.ts server-side request forgery

CVE ID :CVE-2026-6979 Published : April 25, 2026, 12:15 p.m. | 11 hours, 58 minutes ago Description :A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026
VulnerabilitàAlta
CVE-2026-6978 - JiZhiCMS addcache.html htmlspecialchars_decode sql injection

CVE ID :CVE-2026-6978 Published : April 25, 2026, 12:15 p.m. | 11 hours, 58 minutes ago Description :A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument sqls results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 apr 2026

Pagina 2081 di 3175

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.