Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45464 risultati

News
CISA en NCSC waarschuwen voor kwetsbaarheid in Arista VeloCloud

CISA en NCSC waarschuwen voor kwetsbaarheid in Arista VeloCloud Het Amerikaanse Cybersecurity and Infrastructure Security Agency (CISA) en het Nederlandse Nationaal Cyber Security Centrum (NCSC) waarschuwen voor een actief aangevallen kwetsbaarheid in Arista VeloC ... Read more Published Date: Sep 23, 2026 (5 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-93952

CVEfeed Newsroom23 set 2026
VulnerabilitàAlta
CVE-2026-73192 - Apache Sling XSS: XSS possible through XSSAPI.getValidHref()

CVE ID :CVE-2026-73192 Published : Sept. 23, 2026, 9:09 a.m. | 1 hour, 18 minutes ago Description :An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an application, the attacker needs to be able to submit a value which is not correctly sanitized by that library. Upgrade to Apache Sling XSS >= 2.4.12 Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
News
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems ... Read more Published Date: Sep 23, 2026 (5 jours ago) Vulnerabilities has been mentioned in this article. CVE-2026-94127 CVE-2025-53521

CVEfeed Newsroom23 set 2026
News
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on ... Read more Published Date: Sep 23, 2026 (4 jours, 22 heures ago) Vulnerabilities has been mentioned in this article. CVE-2026-87491 CVE-2026-85880 CVE-2026-85046

CVEfeed Newsroom23 set 2026
News
NCSC waarschuwt voor actief misbruikt zerodaylek in F5 BIG-IP

NCSC waarschuwt voor actief misbruikt zerodaylek in F5 BIG-IP Het Nationaal Cyber Security Centrum (NCSC) waarschuwt organisaties voor een ernstige kwetsbaarheid in F5 BIG-IP Access Policy Manager (APM) die monenteel actief wordt misbruikt. F5 heeft beveiligings ... Read more Published Date: Sep 23, 2026 (4 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-94127

CVEfeed Newsroom23 set 2026
VulnerabilitàAlta
CVE-2026-92378 - uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login

CVE ID :CVE-2026-92378 Published : Sept. 23, 2026, 8:17 a.m. | 2 hours, 10 minutes ago Description :A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91817 - Foxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability

CVE ID :CVE-2026-91817 Published : Sept. 23, 2026, 8:17 a.m. | 2 hours, 10 minutes ago Description :A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91818 - Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability

CVE ID :CVE-2026-91818 Published : Sept. 23, 2026, 8:17 a.m. | 2 hours, 10 minutes ago Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91815 - Foxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability

CVE ID :CVE-2026-91815 Published : Sept. 23, 2026, 8:17 a.m. | 2 hours, 10 minutes ago Description :Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91812 - Foxit PDF Editor/Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability

CVE ID :CVE-2026-91812 Published : Sept. 23, 2026, 8:17 a.m. | 2 hours, 10 minutes ago Description :A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges. Severity: 7.9 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91816 - Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

CVE ID :CVE-2026-91816 Published : Sept. 23, 2026, 8:17 a.m. | 2 hours, 10 minutes ago Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91809 - Foxit PDF Editor/Reader Annotation Use-After-Free Information Disclosure Vulnerability

CVE ID :CVE-2026-91809 Published : Sept. 23, 2026, 8:17 a.m. | 28 minutes ago Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 218 di 3789

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.