Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38140 risultati

VulnerabilitàAlta
CVE-2026-31650 - mmc: vub300: fix use-after-free on disconnect

CVE ID :CVE-2026-31650 Published : April 24, 2026, 3:16 p.m. | 55 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix use-after-free on disconnect The vub300 driver maintains an explicit reference count for the controller and its driver data and the last reference can in theory be dropped after the driver has been unbound. This specifically means that the controller allocation must not be device managed as that can lead to use-after-free. Note that the lifetime is currently also incorrectly tied the parent USB device rather than interface, which can lead to memory leaks if the driver is unbound without its device being physically disconnected (e.g. on probe deferral). Fix both issues by reverting to non-managed allocation of the controller. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
News
Governments on high alert after CISA snuffs out Firestarter backdoor on fed network

Governments on high alert after CISA snuffs out Firestarter backdoor on fed network A US federal agency was successfully targeted by a previously unknown backdoor malware called Firestarter, according to CISA cybersnoops and their UK counterparts – neither of which disclosed the agen ... Read more Published Date: Apr 24, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-20362 CVE-2025-20333

CVEfeed Newsroom24 apr 2026
News
VS en VK waarschuwen voor "FIRESTARTER" backdoor in Cisco ASA-firewalls

VS en VK waarschuwen voor "FIRESTARTER" backdoor in Cisco ASA-firewalls vrijdag 24 april 2026, 16:15 door Redactie, 0 reactiesLaatst bijgewerkt: Vandaag, 16:58 De Amerikaanse en Britse overheid waarschuwen voor een backdoor genaamd FIRESTARTER die aanvallers in Cisco ASA- ... Read more Published Date: Apr 24, 2026 (3 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-20362 CVE-2025-20333

CVEfeed Newsroom24 apr 2026
News
Academic Exposure: The Unpatched Flaw Siphoning Student Data from DRC INSIGHT

Academic Exposure: The Unpatched Flaw Siphoning Student Data from DRC INSIGHT A security vulnerability has been unearthed in the DRC INSIGHT software—a platform widely used for proctoring academic exams. The flaw, tracked as CVE-2026-5756, resides in the Central Office Services ... Read more Published Date: Apr 24, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom24 apr 2026
VulnerabilitàAlta
CVE-2026-5367 (CVSS 8.6)

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.

NVD (NIST)24 apr 2026
VulnerabilitàAlta
CVE-2026-5367 - Ovn: ovn: information disclosure via crafted dhcpv6 packets

CVE ID :CVE-2026-5367 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
VulnerabilitàAlta
CVE-2026-5265 - Ovn: ovn: heap over-read in icmp error response generation - security issue

CVE ID :CVE-2026-5265 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
VulnerabilitàAlta
CVE-2026-38743 - Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities

CVE ID :CVE-2026-38743 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request parameters) and full TaskInstance details for DAGs outside their authorized scope. Because HITL prompts and TaskInstance fields routinely carry operator parameters and free-form context attached to a task, the leak widens visibility of DAG-run data beyond the intended per-DAG RBAC boundary for every authenticated user. Users are recommended to upgrade to version 3.2.1 , which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
VulnerabilitàAlta
CVE-2026-40690 - Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users

CVE ID :CVE-2026-40690 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope. Users are recommended to upgrade to version 3.2.1, which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
VulnerabilitàCritica
CVE-2026-21515 (CVSS 9.9)

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

NVD (NIST)24 apr 2026
VulnerabilitàAlta
CVE-2026-21515 - Azure IoT Central Elevation of Privilege Vulnerability

CVE ID :CVE-2026-21515 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
News
The 9.1 CVSS Flaw: Why Millions of Spring Boot Apps May Be Exposed

The 9.1 CVSS Flaw: Why Millions of Spring Boot Apps May Be Exposed In a major update for the Java ecosystem, several critical vulnerabilities have been disclosed in Spring Boot, the framework that powers millions of modern enterprise applications. These flaws—CVE-202 ... Read more Published Date: Apr 24, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom24 apr 2026

Pagina 2094 di 3179

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.