News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38326 risultati
CVE ID :CVE-2026-0972 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-1089 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-10354 Published : April 21, 2026, 3:16 p.m. | 49 minutes ago Description :Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the '/index.php/Speciaal:GefacetteerdZoeken' endpoint parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-41011 Published : April 21, 2026, 3:15 p.m. | 50 minutes ago Description :HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40498 Published : April 21, 2026, 3:01 p.m. | 1 hour, 4 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a static MD5 hash derived from the APP_KEY, which is exposed in the response and logs. Accessing these endpoints reveals sensitive server information (Full Path Disclosure), process IDs, and allows for Resource Exhaustion (DoS) by triggering heavy background tasks repeatedly without any rate limiting. The cron hash is generated using md5(APP_KEY . 'web_cron_hash'). Since this hash is often transmitted via GET requests, it is susceptible to exposure in server logs, browser history, and proxy logs. Furthermore, the lack of rate limiting on these endpoints allows for automated resource exhaustion (DoS) and brute-force attempts. Version 1.8.213 fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-41029 Published : April 21, 2026, 2:59 p.m. | 1 hour, 6 minutes ago Description :SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameter 'phonenumber' in '/private/continue-upload.php'. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Three Silent Vulnerabilities Discovered in the glibc Core The core of many Linux-based operating systems is facing a series of security challenges. Recent advisories for the GNU C Library (glibc) have disclosed three distinct vulnerabilities ranging from hea ... Read more Published Date: Apr 21, 2026 (1 day, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5928 CVE-2026-5450 CVE-2026-5358 CVE-2026-22679 CVE-2026-3308 CVE-2026-3888 CVE-2026-0861 CVE-2025-13151
The Dual CVSS 10.0 RCE Flaws Threatening Spinnaker Pipelines A pair of critical remote code execution (RCE) vulnerabilities has been disclosed in Spinnaker, the heavyweight open-source platform used by tech giants like Adobe, Airbnb, and JPMorgan Chase to manag ... Read more Published Date: Apr 21, 2026 (1 day, 14 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32613 CVE-2026-32604 CVE-2026-5189 CVE-2026-22679 CVE-2025-37164 CVE-2025-54469
CVE ID :CVE-2026-6784 Published : April 21, 2026, 1:16 p.m. | 2 hours, 49 minutes ago Description :Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6777 Published : April 21, 2026, 1:16 p.m. | 49 minutes ago Description :Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6779 Published : April 21, 2026, 1:16 p.m. | 49 minutes ago Description :Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6781 Published : April 21, 2026, 1:16 p.m. | 2 hours, 49 minutes ago Description :Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2162 di 3194