Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38283 risultati

VulnerabilitàAlta
CVE-2026-34064 - nimiq-account: Vesting insufficient funds error can panic

CVE ID :CVE-2026-34064 Published : April 22, 2026, 7:43 p.m. | 25 minutes ago Description :nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `AccountError::InsufficientFunds` when `new_balance balance`, the node crashes while trying to return an error. The `min_cap > balance` precondition is attacker-reachable because the vesting contract creation data (32-byte format) allows encoding `total_amount` without validating `total_amount Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-34063 - network-libp2p: Peer can crash the node by opening discovery protocol substream twice

CVE ID :CVE-2026-34063 Published : April 22, 2026, 7:40 p.m. | 28 minutes ago Description :Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the handler assumes there is at most one inbound and one outbound discovery substream per connection. if a remote peer opens/negotiate the discovery protocol substream a second time on the same connection, the handler hits a `panic!(\"Inbound already connected\")` / `panic!(\"Outbound already connected\")` path instead of failing closed. This causes a remote crash of the networking task (swarm), taking the node's p2p networking offline until restart. The patch for this vulnerability is formally released as part of v1.3.0. No known workarounds are available. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
News
Microsoft issues emergency update for macOS and Linux ASP.NET threat

Microsoft issues emergency update for macOS and Linux ASP.NET threat Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development ... Read more Published Date: Apr 22, 2026 (1 day, 14 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-40372

CVEfeed Newsroom22 apr 2026
VulnerabilitàAlta
CVE-2026-3673 - Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer

CVE ID :CVE-2026-3673 Published : April 22, 2026, 8:16 p.m. | 1 hour, 52 minutes ago Description :An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interpolates tag content into HTML attributes and element content without escaping. This issue affects Frappe: 16.10.10. Severity: 4.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-6019 - BaseCookie.js_output() does not neutralize embedded characters

CVE ID :CVE-2026-6019 Published : April 22, 2026, 8:16 p.m. | 1 hour, 52 minutes ago Description :http.cookies.Morsel.js_output() returns an inline snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. Severity: 2.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-34062 - Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/response

CVE ID :CVE-2026-34062 Published : April 22, 2026, 7:23 p.m. | 45 minutes ago Description :nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_to_end()` on inbound substreams, so a remote peer can send only a partial frame and keep the substream open. because `Behaviour::new` also sets `with_max_concurrent_streams(1000)`, the node exposes a much larger stalled-slot budget than the library default. The patch for this vulnerability is formally released as part of v1.3.0. No known workarounds are available. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-41469 - Beghelli Sicuro24 SicuroWeb Missing Content Security Policy

CVE ID :CVE-2026-41469 Published : April 22, 2026, 7:17 p.m. | 51 minutes ago Description :Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template injection and sandbox escape vulnerabilities present in the same application, the absence of CSP removes the browser-enforced restriction that would otherwise block external script execution, enabling attackers to load arbitrary remote payloads into operator browser sessions. Severity: 5.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-41468 (CVSS 8.7)

Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM manipulation, and persistent browser compromise. Network-adjacent attackers can deliver the complete injection and escape chain via MITM in plaintext HTTP deployments without active user interaction.

NVD (NIST)22 apr 2026
VulnerabilitàAlta
CVE-2026-41468 - Beghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection

CVE ID :CVE-2026-41468 Published : April 22, 2026, 7:17 p.m. | 51 minutes ago Description :Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM manipulation, and persistent browser compromise. Network-adjacent attackers can deliver the complete injection and escape chain via MITM in plaintext HTTP deployments without active user interaction. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-41459 - Xerte Online Toolkits Path Disclosure via /setup

CVE ID :CVE-2026-41459 Published : April 22, 2026, 7:17 p.m. | 51 minutes ago Description :Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. Attackers can send a GET request to the /setup page to access the exposed root_path value rendered in the HTML response, which enables exploitation of path-dependent vulnerabilities such as relative path traversal in connector.php. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàCritica
CVE-2026-34415 (CVSS 9.8)

Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attackers can exploit this flaw combined with authentication bypass and path traversal vulnerabilities to upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on the server.

NVD (NIST)22 apr 2026
VulnerabilitàAlta
CVE-2026-34414 (CVSS 7.1)

Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name parameter in rename commands is not sanitized for path traversal sequences. Attackers can supply a name value containing directory traversal sequences to move files from project media directories to arbitrary locations on the filesystem, potentially overwriting application files, achieving stored cross-site scripting, or combining with other vulnerabilities to achieve unauthenticated remote code execution by moving PHP code files to the application root.

NVD (NIST)22 apr 2026

Pagina 2132 di 3191

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.