Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38343 risultati

VulnerabilitàAlta
CVE-2026-25058 - Vexa's unauthenticated internal transcript endpoint exposed by default

CVE ID :CVE-2026-25058 Published : April 20, 2026, 4:16 p.m. | 1 hour, 11 minutes ago Description :Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector service exposes an internal endpoint `GET /internal/transcripts/{meeting_id}` that returns transcript data for any meeting without any authentication or authorization checks. An unauthenticated attacker can enumerate all meeting IDs, access any user's meeting transcripts without credentials, and steal confidential business conversations, passwords, and/or PII. Version 0.10.0-260419-1910 patches the issue. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6652 - Pagekit CMS StringStorage Template PhpEngine.php evaluate eval injection

CVE ID :CVE-2026-6652 Published : April 20, 2026, 4:16 p.m. | 1 hour, 47 minutes ago Description :A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/modules/view/src/PhpEngine.php of the component StringStorage Template Handler. This manipulation causes improper neutralization of directives in dynamically evaluated code. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-3219 - pip doesn't reject concatenated ZIP and tar archives

CVE ID :CVE-2026-3219 Published : April 20, 2026, 4:16 p.m. | 1 hour, 11 minutes ago Description :pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both. Severity: 4.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-39918 - Vvveb < 1.0.8.1 Code Injection via Installation Endpoint

CVE ID :CVE-2026-39918 Published : 20. April 2026 14:46 | 40 Minuten ago Description :Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation. Attackers can inject arbitrary PHP code by breaking out of the string context in the define statement to achieve unauthenticated remote code execution as the web server user. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6651 - erponline.xyz ERP Online Inventory Edit Item cross site scripting

CVE ID :CVE-2026-6651 Published : April 20, 2026, 4:16 p.m. | 1 hour, 10 minutes ago Description :A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item Name results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
News
Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware

Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware Threat actors are now weaponizing QEMU, a legitimate open-source machine emulator and virtualizer, as a covert backdoor to steal credentials and deliver ransomware without triggering endpoint security ... Read more Published Date: Apr 20, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-26399 CVE-2025-5777

CVEfeed Newsroom20 apr 2026
VulnerabilitàAlta
CVE-2026-6650 - Z-BlogPHP ZBA File app_upload.php UnPack unrestricted upload

CVE ID :CVE-2026-6650 Published : April 20, 2026, 4:16 p.m. | 1 hour, 10 minutes ago Description :A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/AppCentre/app_upload.php of the component ZBA File Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6649 - Qibo CMS headers server-side request forgery

CVE ID :CVE-2026-6649 Published : 20. April 2026 14:16 | 1 Stunde, 10 Minuten ago Description :A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a manipulation of the argument starts can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6369 - Exposed Session Token in canonical-livepatch client snap

CVE ID :CVE-2026-6369 Published : 20. April 2026 14:16 | 1 Stunde, 10 Minuten ago Description :An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-5760 - CVE-2026-5760

CVE ID :CVE-2026-5760 Published : 20. April 2026 14:16 | 1 Stunde, 10 Minuten ago Description :SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment(). Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-4048 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

CVE ID :CVE-2026-4048 Published : 20. April 2026 14:16 | 1 Stunde, 10 Minuten ago Description :OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-33558 - Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output

CVE ID :CVE-2026-33558 Published : 20. April 2026 14:16 | 1 Stunde, 10 Minuten ago Description :Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the requests and responses output log. The entire lists of impacted requests and responses are: * AlterConfigsRequest * AlterUserScramCredentialsRequest * ExpireDelegationTokenRequest * IncrementalAlterConfigsRequest * RenewDelegationTokenRequest * SaslAuthenticateRequest * createDelegationTokenResponse * describeDelegationTokenResponse * SaslAuthenticateResponse This issue affects Apache Kafka: from any version supported the listed API above through v3.9.1, v4.0.0. We advise the Kafka users to upgrade to v3.9.2, v4.0.1, or later to avoid this vulnerability. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026

Pagina 2179 di 3196

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.