Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38217 risultati

VulnerabilitàCritica
CVE-2026-33102 (CVSS 9.3)

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

NVD (NIST)23 apr 2026
VulnerabilitàCritica
CVE-2026-32210 (CVSS 9.3)

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

NVD (NIST)23 apr 2026
VulnerabilitàAlta
CVE-2026-32172 (CVSS 8)

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

NVD (NIST)23 apr 2026
VulnerabilitàCritica
CVE-2026-26210 (CVSS 9.8)

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can send a crafted pickle payload to the exposed ZMQ socket to execute arbitrary code on the server with the privileges of the ktransformers process.

NVD (NIST)23 apr 2026
VulnerabilitàAlta
CVE-2026-26150 (CVSS 8.6)

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

NVD (NIST)23 apr 2026
VulnerabilitàCritica
CVE-2026-24303 (CVSS 9.6)

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

NVD (NIST)23 apr 2026
VulnerabilitàAlta
CVE-2026-2708 - Libsoup: libsoup: http request smuggling via duplicate content-length headers

CVE ID :CVE-2026-2708 Published : April 23, 2026, 9:51 p.m. | 18 minutes ago Description :A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàCritica
CVE-2026-6942 (CVSS 9.8)

radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication.

NVD (NIST)23 apr 2026
VulnerabilitàAlta
CVE-2026-6940 (CVSS 7.1)

radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to project marker files outside the project storage boundary to cause recursive deletion of attacker-chosen directories with permissions of the radare2 process, resulting in integrity and availability loss.

NVD (NIST)23 apr 2026
VulnerabilitàAlta
CVE-2026-6941 - radare2 < 6.1.4 Project Notes Path Traversal via Symlink

CVE ID :CVE-2026-6941 Published : April 23, 2026, 9:16 p.m. | 54 minutes ago Description :radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-6942 - radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypass

CVE ID :CVE-2026-6942 Published : April 23, 2026, 9:16 p.m. | 54 minutes ago Description :radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-6940 - radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion

CVE ID :CVE-2026-6940 Published : April 23, 2026, 9:16 p.m. | 54 minutes ago Description :radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to project marker files outside the project storage boundary to cause recursive deletion of attacker-chosen directories with permissions of the radare2 process, resulting in integrity and availability loss. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026

Pagina 2111 di 3185

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.