News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38308 risultati
CVE ID :CVE-2026-40161 Published : April 21, 2026, 5:16 p.m. | 49 minutes ago Description :Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0.0 to 1.10.0, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing serverURL to an attacker-controlled endpoint. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA Adds Eight Actively Exploited Vulnerabilities to KEV Catalog CISA expanded its Known Exploited Vulnerabilities (KEV) catalog on April 20, 2026, adding eight security flaws spanning enterprise print management, CI/CD platforms, CMS infrastructure, appliance mana ... Read more Published Date: Apr 21, 2026 (1 day, 11 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2025-32975 CVE-2025-48700 CVE-2025-2749 CVE-2024-27199 CVE-2023-27351
CVE ID :CVE-2026-40565 Published : April 21, 2026, 3:52 p.m. | 13 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php converts plain-text URLs in email bodies into HTML anchor tags without escaping double-quote characters (") in the URL. HTMLPurifier (called first via getCleanBody()) preserves literal " characters in text nodes. linkify() then wraps URLs including those " chars inside an unescaped href="..." attribute, breaking out of the href and injecting arbitrary HTML attributes. Version 1.8.213 fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial-to-IP Converters Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex that could be exploited to hijack susceptible devices and tamper ... Read more Published Date: Apr 21, 2026 (1 day, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32965 CVE-2026-32964 CVE-2026-32963 CVE-2026-32962 CVE-2026-32961 CVE-2026-32960 CVE-2026-32959 CVE-2026-32958 CVE-2026-32957 CVE-2026-32956 CVE-2026-32955 CVE-2026-34197 CVE-2026-33032 CVE-2025-70082 CVE-2025-67041 CVE-2025-67039 CVE-2025-67038 CVE-2025-67037 CVE-2025-67036 CVE-2025-67035 CVE-2025-67034 CVE-2024-24487 CVE-2015-5621
CVE ID :CVE-2025-15638 Published : April 21, 2026, 3:34 p.m. | 31 minutes ago Description :Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2017-20230 Published : April 21, 2026, 3:26 p.m. | 39 minutes ago Description :Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-3298 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-5789 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-31014 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :Dovestones Softwares AD Self Update Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-31013 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :Dovestones Softwares ADPhonebook Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-31018 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :In Dolibarr ERP & CRM Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-31019 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in full remote code execution with the ability to execute arbitrary operating system commands on the server. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2159 di 3193