News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38326 risultati
NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
CVE ID :CVE-2026-5965 Published : April 21, 2026, 4:16 a.m. | 7 hours, 49 minutes ago Description :NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability A proof-of-concept (PoC) exploit has been publicly released for a newly disclosed vulnerability in Microsoft’s Snipping Tool that allows attackers to silently steal users’ Net-NTLM credential hashes b ... Read more Published Date: Apr 21, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33829
CVE ID :CVE-2026-6674 Published : April 21, 2026, 3:16 a.m. | 8 hours, 49 minutes ago Description :The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6675 Published : April 21, 2026, 3:16 a.m. | 8 hours, 49 minutes ago Description :The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, and including, 2.2.0. This is due to insufficient authorization checks and missing server-side validation of the recipient email address supplied via a public REST API route. This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient of their choosing through the affected WordPress site's mail server, effectively turning the site into an open mail relay. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40497 Published : April 21, 2026, 3:16 a.m. | 8 hours, 49 minutes ago Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes ``, ``, ``, `` but does NOT strip `` tags. The mailbox signature field is saved via POST /mailbox/settings/{id} and later rendered unescaped via `{!! $conversation->getSignatureProcessed([], true) !!}` in conversation views. CSP allows `style-src * 'self' 'unsafe-inline'`, so injected inline styles execute freely. An attacker with access to mailbox settings (admin or agent with mailbox permission) can inject CSS attribute selectors to exfiltrate the CSRF token of any agent/admin who views a conversation in that mailbox. With the CSRF token, the attacker can perform any state-changing action as the victim (create admin accounts, change email/password, etc.) — privilege escalation from agent to admin. This is the result of an incomplete fix of GHSA-jqjf-f566-485j. That advisory reported XSS via mailbox signature. The fix applied `Helper::stripDangerousTags()` to the signature before saving. However, `stripDangerousTags()` only removes `script`, `form`, `iframe`, and `object` tags — it does NOT strip `` tags, leaving CSS injection possible. Version 1.8.213 contains an updated fix. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical Gardyn Smart Gardens Vulnerabilities Let Attackers Control Devices Remotely The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about severe vulnerabilities in Gardyn Home Kit smart garden systems. Carrying a maximum severity score of 9.3 ... Read more Published Date: Apr 21, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32662 CVE-2026-32646 CVE-2026-28767 CVE-2026-28766 CVE-2026-25197 CVE-2025-10681 CVE-2025-1242
CISA Warns of Active Exploitation in Cisco, PaperCut, and Zimbra The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog, adding eight high-impact flaws. The update comes following confirmed evidenc ... Read more Published Date: Apr 21, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22679 CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2025-2566 CVE-2025-32975 CVE-2025-48700 CVE-2025-20188 CVE-2025-2749 CVE-2024-27199 CVE-2023-32315 CVE-2023-27351
Critical Anthropic’s MCP Vulnerability Enables Remote Code Execution Attacks A critical flaw in Anthropic’s Model Context Protocol (MCP) exposes over 150 million downloads to potential compromise. The vulnerability could enable full system takeover across up to 200,000 servers ... Read more Published Date: Apr 21, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.
Progress Kemp LoadMaster Alert: Multiple RCE and WAF Bypass Flaws Patched The Progress Kemp LoadMaster team has confirmed a significant security event involving five high-severity vulnerabilities affecting its application delivery controllers. These flaws, which impact both ... Read more Published Date: Apr 21, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4048 CVE-2026-3519 CVE-2026-3518 CVE-2026-3517 CVE-2026-39813 CVE-2026-39808 CVE-2026-22679 CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2025-32975 CVE-2025-48700 CVE-2025-2749 CVE-2024-27199 CVE-2023-27351
ASUSTOR Issues Critical Patch: Command Injection Vulnerability Threatens ADM Users ASUSTOR has issued an urgent security advisory regarding a high-severity command injection vulnerability impacting its ASUSTOR Data Master (ADM) operating system. Identified as CVE-2026-6644, this fla ... Read more Published Date: Apr 21, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-6644 CVE-2026-22679 CVE-2026-27728 CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2026-24936 CVE-2025-32975 CVE-2025-48700 CVE-2025-2749 CVE-2024-27199 CVE-2023-27351
CVE ID :CVE-2026-6058 Published : April 21, 2026, 2:16 a.m. | 9 hours, 49 minutes ago Description :** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authenticated administrator to visit the “AP Select” page while a malformed SSID is present. Severity: 4.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2167 di 3194