Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38258 risultati

VulnerabilitàAlta
CVE-2026-4106 - HT Mega < 3.0.7 – Unauthenticated PII Disclosure

CVE ID :CVE-2026-4106 Published : April 23, 2026, 7:16 a.m. | 6 hours, 53 minutes ago Description :The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-34488 - IP Setting Software DLL Search Path Insecure Library Loading Vulnerability

CVE ID :CVE-2026-34488 Published : April 23, 2026, 7:16 a.m. | 6 hours, 53 minutes ago Description :IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrative privileges. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2025-10549 - DLL Hijacking in EfficientLab Controlio Leads to Local Privilege Escalation

CVE ID :CVE-2025-10549 Published : April 23, 2026, 7:16 a.m. | 6 hours, 53 minutes ago Description :EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT AUTHORITY\SYSTEM. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
News
Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System

Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System A high-severity privilege escalation vulnerability, dubbed Pack2TheRoot (CVE-2026-41651, CVSS 3.1: 8.8), has been publicly disclosed by Deutsche Telekom’s Red Team, affecting multiple major Linux dist ... Read more Published Date: Apr 23, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-41651

CVEfeed Newsroom23 apr 2026
News
Apple Fixes Notification Privacy Flaw That Allowed FBI to Access Deleted Signal Messages

Apple Fixes Notification Privacy Flaw That Allowed FBI to Access Deleted Signal Messages Apple released iOS 26.4.2 and iPadOS 26.4.2 on April 22, 2026, to patch a critical notification privacy vulnerability that allowed law enforcement to extract Signal message content from iPhones — even ... Read more Published Date: Apr 23, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-28950 CVE-2026-41651

CVEfeed Newsroom23 apr 2026
VulnerabilitàAlta
CVE-2026-41988 - Apache UUID Unexpected Write Vulnerability

CVE ID :CVE-2026-41988 Published : April 23, 2026, 5:16 a.m. | 8 hours, 53 minutes ago Description :uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue. Severity: 3.2 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-41990 - Libgcrypt Dilithium Signature Validation Buffer Overflow

CVE ID :CVE-2026-41990 Published : April 23, 2026, 5:16 a.m. | 8 hours, 53 minutes ago Description :Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-41989 - Libgcrypt Cryptographic Buffer Overflow Denial of Service

CVE ID :CVE-2026-41989 Published : April 23, 2026, 5:16 a.m. | 8 hours, 53 minutes ago Description :Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-41233 - Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()

CVE ID :CVE-2026-41233 Published : April 23, 2026, 5:16 a.m. | 8 hours, 53 minutes ago Description :Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permission. This allows a reseller to attribute newly created domains to any other admin, bypassing their own domain quota (since the wrong admin's `domains_used` counter is incremented) and potentially exhausting another admin's quota. Version 2.3.6 fixes the issue. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-41232 - Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email Spoofing

CVE ID :CVE-2026-41232 Published : April 23, 2026, 5:16 a.m. | 6 hours, 53 minutes ago Description :Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to `validateLocalDomainOwnership()`. This causes the ownership check to always pass for non-existent "domains," allowing any authenticated customer to add sender aliases for email addresses on domains belonging to other customers. Postfix's `sender_login_maps` then authorizes the attacker to send emails as those addresses. Version 2.3.6 fixes the issue. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
VulnerabilitàAlta
CVE-2026-40529 - Kanata ALAYA CMS SQL Injection

CVE ID :CVE-2026-40529 Published : April 23, 2026, 5:16 a.m. | 6 hours, 53 minutes ago Description :CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 apr 2026
News
Linux Privilege Escalation: “Pack2TheRoot” Flaw Impacts Major Distributions

Linux Privilege Escalation: “Pack2TheRoot” Flaw Impacts Major Distributions A long-standing security flaw has been unearthed in a core component of the modern Linux desktop and server ecosystem. Known as Pack2TheRoot, this critical vulnerability resides in PackageKit, a D-Bus ... Read more Published Date: Apr 23, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-3844 CVE-2026-41651 CVE-2026-33626 CVE-2026-33825 CVE-2026-22679 CVE-2026-35386 CVE-2026-35093

CVEfeed Newsroom23 apr 2026

Pagina 2123 di 3189

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.