Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38258 risultati

VulnerabilitàAlta
CVE-2026-40470 - Hackage package and doc upload stored XSS vulnerability

CVE ID :CVE-2026-40470 Published : April 23, 2026, 4:16 p.m. | 1 hour, 53 minutes ago Description :A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP credentials browses to the package pages or documentation uploaded by a malicious package maintainer, their session can be hijacked to upload packages or documentation, amend maintainers or other package metadata, or perform any other action the user is authorised to do. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-41239 - DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode

CVE ID :CVE-2026-41239 Published : April 23, 2026, 4:16 p.m. | 1 hour, 53 minutes ago Description :DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-23751 - Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting

CVE ID :CVE-2026-23751 Published : April 23, 2026, 2:46 p.m. | 1 hour, 23 minutes ago Description :Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling techniques to instantiate a remote System.Net.WebClient object and read arbitrary files from the server filesystem, write attacker-controlled files to the server, or coerce NTLMv2 authentication to an attacker-controlled host, enabling sensitive credential disclosure, denial of service, remote code execution, or lateral movement depending on service account privileges and network environment. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-41238 - DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback

CVE ID :CVE-2026-41238 Published : April 23, 2026, 4:16 p.m. | 1 hour, 53 minutes ago Description :DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes — including event handlers — through sanitization. Version 3.4.0 fixes the issue. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2025-62373 - Pipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializer

CVE ID :CVE-2025-62373 Published : April 23, 2026, 4:16 p.m. | 1 hour, 53 minutes ago Description :Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integration. The class's `deserialize()` method uses Python's `pickle.loads()` on data received from WebSocket clients without any validation or sanitization. This means that a malicious WebSocket client can send a crafted pickle payload to execute arbitrary code on the Pipecat server. The vulnerable code resides in `src/pipecat/serializers/livekit.py` (around line 73), where untrusted WebSocket message data is passed directly into `pickle.loads()` for deserialization. If a Pipecat server is configured to use LivekitFrameSerializer and is listening on an external interface (e.g. 0.0.0.0), an attacker on the network (or the internet, if the service is exposed) could achieve remote code execution (RCE) on the server by sending a malicious pickle payload. Version 0.0.94 contains a fix. Users of Pipecat should avoid or replace unsafe deserialization and improve network security configuration. The best mitigation is to stop using the vulnerable LivekitFrameSerializer altogether. Those who require LiveKit functionality should upgrade to the latest Pipecat version and switch to the recommended `LiveKitTransport` or another secure method provided by the framework. Additionally, always follow secure coding practices: never trust client-supplied data, and avoid Python pickle (or similar unsafe deserialization) in network-facing components. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
News
Windows Python Users Warned of High-Severity “asyncio” Memory Flaw

Windows Python Users Warned of High-Severity “asyncio” Memory Flaw Python developers and system administrators on Windows are being urged to update their environments following the discovery of a high-severity vulnerability in the standard library. The flaw, tracked ... Read more Published Date: Apr 23, 2026 (3 days, 16 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom23 apr 2026
News
Mailcow Critical Alert: Unauthenticated XSS Threatens Admin Takeover

Mailcow Critical Alert: Unauthenticated XSS Threatens Admin Takeover The popular open-source groupware suite mailcow: dockerized is facing a high-stakes security challenge. A critical Stored Cross-Site Scripting (XSS) vulnerability has been discovered in the platform’s ... Read more Published Date: Apr 23, 2026 (3 days, 16 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom23 apr 2026
News
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories

ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes.The supply chain is messy. P ... Read more Published Date: Apr 23, 2026 (2 days, 15 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197 CVE-2026-33032 CVE-2026-27175 CVE-2026-27174 CVE-2025-22952 CVE-2024-57046 CVE-2024-32114

CVEfeed Newsroom23 apr 2026
VulnerabilitàAlta
CVE-2025-66286 - Webkitgtk: authorization bypass through webpage::send-request signal handler

CVE ID :CVE-2025-66286 Published : April 23, 2026, 1:16 p.m. | 4 hours, 54 minutes ago Description :An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-39440 - WordPress FunnelFormsPro plugin <= 3.8.1 - Remote Code Execution (RCE) vulnerability

CVE ID :CVE-2026-39440 Published : April 23, 2026, 1:16 p.m. | 4 hours, 53 minutes ago Description :Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2025-13763 - Libopensc: opensc: multiple uses of uninitialized variable

CVE ID :CVE-2025-13763 Published : April 23, 2026, 1:16 p.m. | 4 hours, 54 minutes ago Description :Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
News
Unpatch Ollama Flaw: Malicious Model Uploads Can Leak Server Heap Memory

Unpatch Ollama Flaw: Malicious Model Uploads Can Leak Server Heap Memory A critical unauthenticated remote information disclosure vulnerability has been uncovered in Ollama, the popular open-source tool used to run LLMs on macOS, Windows, and Linux. The flaw, tracked as CV ... Read more Published Date: Apr 23, 2026 (2 days, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom23 apr 2026

Pagina 2120 di 3189

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.