Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38308 risultati

VulnerabilitàAlta
CVE-2026-22754 - ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules

CVE ID :CVE-2026-22754 Published : April 22, 2026, 6:16 a.m. | 1 hour, 51 minutes ago Description :Vulnerability in Spring Spring Security. If an application uses to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-22753 - Servlet Path Not Correctly Included in Path Matching of HttpSecurity#securityMatchers

CVE ID :CVE-2026-22753 Published : April 22, 2026, 6:16 a.m. | 1 hour, 51 minutes ago Description :Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-40451 - DeepL Chrome Cross-Site Scripting (XSS)

CVE ID :CVE-2026-40451 Published : April 22, 2026, 5:16 a.m. | 2 hours, 51 minutes ago Description :DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's browser, and inject malicious HTML into web pages viewed by the user. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-22748 - Potential Security Misconfiguration when Using withIssuerLocation

CVE ID :CVE-2026-22748 Published : April 22, 2026, 6:16 a.m. | 1 hour, 51 minutes ago Description :Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-22747 - Unauthorized User Impersonation when Using X.509 Client Certificates

CVE ID :CVE-2026-22747 Published : April 22, 2026, 6:16 a.m. | 1 hour, 51 minutes ago Description :Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-22746 - User Attribute Enumeration when Using DaoAuthenticationProvider

CVE ID :CVE-2026-22746 Published : April 22, 2026, 6:16 a.m. | 1 hour, 51 minutes ago Description :Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
News
Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability

Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability Microsoft has issued an emergency out-of-band (OOB) security update for .NET 10, releasing version 10.0.7 on April 21, 2026, to address a critical elevation of privilege vulnerability discovered in th ... Read more Published Date: Apr 22, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-40372

CVEfeed Newsroom22 apr 2026
VulnerabilitàAlta
CVE-2026-6835 - aEnrich|a+HCM - Arbitrary File Upload

CVE ID :CVE-2026-6835 Published : April 22, 2026, 4:16 a.m. | 3 hours, 51 minutes ago Description :The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-6834 - aEnrich|a+HRD - Missing Authorization

CVE ID :CVE-2026-6834 Published : April 22, 2026, 4:16 a.m. | 3 hours, 51 minutes ago Description :The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-6833 - aEnrich|a+HRD - SQL Injection

CVE ID :CVE-2026-6833 Published : April 22, 2026, 4:16 a.m. | 3 hours, 51 minutes ago Description :The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-6408 - Tanium addressed an information disclosure vulnerability in Tanium Server.

CVE ID :CVE-2026-6408 Published : April 22, 2026, 3:16 a.m. | 4 hours, 51 minutes ago Description :Tanium addressed an information disclosure vulnerability in Tanium Server. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-41458 - OwnTone Server < 29.1 Race Condition DoS via DAAP Login

CVE ID :CVE-2026-41458 Published : April 22, 2026, 3:16 a.m. | 2 hours, 51 minutes ago Description :OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026

Pagina 2146 di 3193

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.