News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38283 risultati
CVE ID :CVE-2026-6355 Published : April 22, 2026, 2:17 p.m. | 1 hour, 51 minutes ago Description :A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to unauthorized access to sensitive information and unauthorized changes to the tenant's configuration. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.
CVE ID :CVE-2026-6855 Published : April 22, 2026, 1:16 p.m. | 51 minutes ago Description :A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6857 Published : April 22, 2026, 1:16 p.m. | 51 minutes ago Description :A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41651 Published : April 22, 2026, 2:17 p.m. | 1 hour, 51 minutes ago Description :PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction has already been authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING. 2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags. 3. Late flag read at execution time (lines 2273–2277): The scheduler's idle callback reads cached_transaction_flags at dispatch time, not at authorization time. If flags were overwritten between authorization and execution, the backend sees the attacker's flags. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
NVIDIA Fixes High-Severity Flaws in KAI Scheduler and CUDA-Q NVIDIA has released a series of software updates to address high-severity vulnerabilities in its KAI Scheduler and CUDA-Q platforms. The vulnerabilities range from unauthorized API access to memory co ... Read more Published Date: Apr 22, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-0539 Published : April 22, 2026, 1:02 p.m. | 1 hour, 6 minutes ago Description :Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate their privileges by overwriting the service binary with arbitrary contents. This service binary is automatically launched with NT\SYSTEM privileges on boot. This issue affects all versions after 22.6.22.1329 and was fixed in 25.12.3.1745. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Mozilla: Firefox kwetsbaarheden door Claude Mythos van Anthropic ontdekt Mozilla heeft deze week een nieuwe versie van Firefox uitgebracht waarin 271 kwetsbaarheden zijn verholpen die door een AI-model van Anthropic zijn ontdekt. Het gaat om een vroege versie van Claude My ... Read more Published Date: Apr 22, 2026 (1 day, 15 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-6758 CVE-2026-6757 CVE-2026-6746
GitLab Security Update: High-Severity Vulnerabilities Patched in April Release GitLab has released a vital set of security updates for both Community Edition (CE) and Enterprise Edition (EE) to address a range of vulnerabilities, including high-severity flaws that could allow un ... Read more Published Date: Apr 22, 2026 (1 day, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-6515 CVE-2026-5816 CVE-2026-5377 CVE-2026-5262 CVE-2026-4922 CVE-2025-9957 CVE-2026-33626 CVE-2026-40342 CVE-2026-33825 CVE-2026-22679 CVE-2026-1868 CVE-2024-8312 CVE-2024-6826
CVE-2026-40342: CVSS 10.0 Path Traversal to RCE in Firebird Database Researchers have disclosed a critical-severity vulnerability in Firebird, the long-standing relational database with roots dating back to 1981, that allows attackers to execute arbitrary code with the ... Read more Published Date: Apr 22, 2026 (1 day, 14 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33626 CVE-2026-40342 CVE-2026-33825 CVE-2026-22679
Oracle dicht 481 kwetsbaarheden in patchronde april met meerdere kritieke lekken Oracle heeft tijdens de patchronde van april kwetsbaarheden in een groot aantal producten verholpen. Het gaat onder andere om Oracle Communications, Financial Services Applications en Fusion Middlewa ... Read more Published Date: Apr 22, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-21992
Pagina 2138 di 3191