Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38308 risultati

VulnerabilitàAlta
CVE-2026-6743 - WebSystems WebTOTUM Calendar cross site scripting

CVE ID :CVE-2026-6743 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-5652 - Authorization Bypass Through User-Controlled Key in Crafty Controller

CVE ID :CVE-2026-5652 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation. Severity: 9.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-40592 - FreeScout's cross-user undo reply allows mailbox peers to recall another agent's outbound reply

CVE ID :CVE-2026-40592 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify that the current user created the reply being undone. In a shared mailbox, one agent can therefore recall another agent's just-sent reply during the 15-second undo window. Version 1.8.214 fixes the vulnerability. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-41183 - FreeScout allows non-folder conversation queries to disclose assigned-only hidden conversations

CVE ID :CVE-2026-41183 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX filter path still reveal conversations that should be hidden. Version 1.8.215 fixes the vulnerability. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-41190 - FreeScout has assigned-only visibility bypass via save_draft that allows hidden conversation draft injection

CVE ID :CVE-2026-41190 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, direct conversation view correctly blocks users who are neither the assignee nor the creator. The `save_draft` AJAX path is weaker. A direct POST can create a draft inside a conversation that is hidden in the UI. Version 1.8.215 fixes the vulnerability. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-41189 - FreeScout has assigned-only visibility bypass that allows editing hidden customer-authored threads

CVE ID :CVE-2026-41189 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::edit()`, which checks mailbox access but does not apply the assigned-only restriction from `ConversationPolicy`. A user who cannot view a conversation can still load and edit customer-authored threads inside it. Version 1.8.215 fixes the vulnerability. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-41191 - FreeScout's signature only mailbox permission allows unauthorized mailbox chat setting changes

CVE ID :CVE-2026-41191 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave()` persists `chat_start_new` outside the allowed-field filter. A user with only the mailbox `sig` permission sees only the signature field in the UI, but can still change the hidden mailbox-wide chat setting via direct POST. Version 1.8.215 fixes the vulnerability. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-40584 - RansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information Exposure

CVE ID :CVE-2026-40584 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries marked as private may be unintentionally retained in API responses, allowing unauthorized disclosure of non-public location information. This vulnerability is fixed in 1.9.0. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-40586 - blueprintUE: Login Endpoint Has No Rate Limiting, Lockout, or Brute-Force Protection

CVE ID :CVE-2026-40586 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of any kind. Failed authentication attempts are processed at full network speed with no IP-based rate limiting, no per-account attempt counter, no temporary lockout, no progressive delay (Tarpit), and no CAPTCHA challenge. An attacker can submit an unlimited number of credential guesses. The password policy (10+ characters, mixed case, digit, special character) reduces the effective keyspace but does not prevent dictionary attacks, credential stuffing from breached databases, or targeted attacks against known users with predictable passwords. This vulnerability is fixed in 4.2.0. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-40589 - FreeScout has Customer Edit Cross-Mailbox Email Takeover

CVE ID :CVE-2026-40589 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an email address already owned by a hidden customer in another mailbox. The server discloses the hidden customer’s name and profile URL in the success flash, reassigns the hidden email to the visible customer, and rebinds hidden-mailbox conversations for that email to the visible customer. Version 1.8.214 fixes the issue. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-40590 - FreeScout's Customer AJAX Create Modifies Hidden Existing Customer

CVE ID :CVE-2026-40590 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a “Create a new customer” flow via POST /customers/ajax with action=create. Under limited visibility, the endpoint drops unique-email validation. If the supplied email already belongs to a hidden customer, Customer::create() reuses that hidden customer object and fills empty profile fields from attacker-controlled input. Version 1.8.214 fixes the vulnerability. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-40591 - FreeScout: Improper Authorization in Phone Conversation Creation Enables Cross-Mailbox Hidden Customer Modification

CVE ID :CVE-2026-40591 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in the backend without enforcing mailbox-scoped customer visibility. As a result, a low-privileged agent who can create a phone conversation in Mailbox A can bind the new Mailbox A phone conversation to a hidden customer from Mailbox B and add a new alias email to that hidden customer record by supplying `to_email`. Version 1.8.214 fixes the vulnerability. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026

Pagina 2157 di 3193

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.