News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38258 risultati
CVE ID :CVE-2026-4106 Published : April 23, 2026, 7:16 a.m. | 6 hours, 53 minutes ago Description :The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-34488 Published : April 23, 2026, 7:16 a.m. | 6 hours, 53 minutes ago Description :IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrative privileges. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-10549 Published : April 23, 2026, 7:16 a.m. | 6 hours, 53 minutes ago Description :EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System A high-severity privilege escalation vulnerability, dubbed Pack2TheRoot (CVE-2026-41651, CVSS 3.1: 8.8), has been publicly disclosed by Deutsche Telekom’s Red Team, affecting multiple major Linux dist ... Read more Published Date: Apr 23, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-41651
Apple Fixes Notification Privacy Flaw That Allowed FBI to Access Deleted Signal Messages Apple released iOS 26.4.2 and iPadOS 26.4.2 on April 22, 2026, to patch a critical notification privacy vulnerability that allowed law enforcement to extract Signal message content from iPhones — even ... Read more Published Date: Apr 23, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-28950 CVE-2026-41651
CVE ID :CVE-2026-41988 Published : April 23, 2026, 5:16 a.m. | 8 hours, 53 minutes ago Description :uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue. Severity: 3.2 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41990 Published : April 23, 2026, 5:16 a.m. | 8 hours, 53 minutes ago Description :Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41989 Published : April 23, 2026, 5:16 a.m. | 8 hours, 53 minutes ago Description :Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41233 Published : April 23, 2026, 5:16 a.m. | 8 hours, 53 minutes ago Description :Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permission. This allows a reseller to attribute newly created domains to any other admin, bypassing their own domain quota (since the wrong admin's `domains_used` counter is incremented) and potentially exhausting another admin's quota. Version 2.3.6 fixes the issue. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41232 Published : April 23, 2026, 5:16 a.m. | 6 hours, 53 minutes ago Description :Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to `validateLocalDomainOwnership()`. This causes the ownership check to always pass for non-existent "domains," allowing any authenticated customer to add sender aliases for email addresses on domains belonging to other customers. Postfix's `sender_login_maps` then authorizes the attacker to send emails as those addresses. Version 2.3.6 fixes the issue. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40529 Published : April 23, 2026, 5:16 a.m. | 6 hours, 53 minutes ago Description :CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Linux Privilege Escalation: “Pack2TheRoot” Flaw Impacts Major Distributions A long-standing security flaw has been unearthed in a core component of the modern Linux desktop and server ecosystem. Known as Pack2TheRoot, this critical vulnerability resides in PackageKit, a D-Bus ... Read more Published Date: Apr 23, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-3844 CVE-2026-41651 CVE-2026-33626 CVE-2026-33825 CVE-2026-22679 CVE-2026-35386 CVE-2026-35093
Pagina 2123 di 3189