Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38326 risultati

VulnerabilitàAlta
CVE-2026-0972 - GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances

CVE ID :CVE-2026-0972 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-1089 - User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS Lookups

CVE ID :CVE-2026-1089 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2025-10354 - Reflected Cross-Site Scripting (XSS) in Semantic MediaWiki

CVE ID :CVE-2025-10354 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the '/index.php/Speciaal:GefacetteerdZoeken' endpoint parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2025-41011 - HTML injection in PHP Point Of Sale

CVE ID :CVE-2025-41011 Published : April 21, 2026, 3:15 p.m. | 50 minutes ago Description :HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-40498 - FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron

CVE ID :CVE-2026-40498 Published : April 21, 2026, 3:01 p.m. | 1 hour, 4 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a static MD5 hash derived from the APP_KEY, which is exposed in the response and logs. Accessing these endpoints reveals sensitive server information (Full Path Disclosure), process IDs, and allows for Resource Exhaustion (DoS) by triggering heavy background tasks repeatedly without any rate limiting. The cron hash is generated using md5(APP_KEY . 'web_cron_hash'). Since this hash is often transmitted via GET requests, it is susceptible to exposure in server logs, browser history, and proxy logs. Furthermore, the lack of rate limiting on these endpoints allows for automated resource exhaustion (DoS) and brute-force attempts. Version 1.8.213 fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2025-41029 - SQL injection in Zeon Academy Pro by Zeon Global Tech

CVE ID :CVE-2025-41029 Published : April 21, 2026, 2:59 p.m. | 1 hour, 6 minutes ago Description :SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameter 'phonenumber' in '/private/continue-upload.php'. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
News
Three Silent Vulnerabilities Discovered in the glibc Core

Three Silent Vulnerabilities Discovered in the glibc Core The core of many Linux-based operating systems is facing a series of security challenges. Recent advisories for the GNU C Library (glibc) have disclosed three distinct vulnerabilities ranging from hea ... Read more Published Date: Apr 21, 2026 (1 day, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5928 CVE-2026-5450 CVE-2026-5358 CVE-2026-22679 CVE-2026-3308 CVE-2026-3888 CVE-2026-0861 CVE-2025-13151

CVEfeed Newsroom21 apr 2026
News
The Dual CVSS 10.0 RCE Flaws Threatening Spinnaker Pipelines

The Dual CVSS 10.0 RCE Flaws Threatening Spinnaker Pipelines A pair of critical remote code execution (RCE) vulnerabilities has been disclosed in Spinnaker, the heavyweight open-source platform used by tech giants like Adobe, Airbnb, and JPMorgan Chase to manag ... Read more Published Date: Apr 21, 2026 (1 day, 14 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32613 CVE-2026-32604 CVE-2026-5189 CVE-2026-22679 CVE-2025-37164 CVE-2025-54469

CVEfeed Newsroom21 apr 2026
VulnerabilitàAlta
CVE-2026-6784 - Memory safety bugs fixed in Firefox 150 and Thunderbird 150

CVE ID :CVE-2026-6784 Published : April 21, 2026, 1:16 p.m. | 2 hours, 49 minutes ago Description :Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-6777 - Other issue in the Networking: DNS component

CVE ID :CVE-2026-6777 Published : April 21, 2026, 1:16 p.m. | 49 minutes ago Description :Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-6779 - Other issue in the JavaScript Engine component

CVE ID :CVE-2026-6779 Published : April 21, 2026, 1:16 p.m. | 49 minutes ago Description :Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-6781 - Denial-of-service in the Audio/Video: Playback component

CVE ID :CVE-2026-6781 Published : April 21, 2026, 1:16 p.m. | 2 hours, 49 minutes ago Description :Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026

Pagina 2162 di 3194

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.