Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38343 risultati

VulnerabilitàAlta
CVE-2026-3518 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

CVE ID :CVE-2026-3518 Published : 20. April 2026 14:16 | 1 Stunde, 10 Minuten ago Description :OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-3519 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

CVE ID :CVE-2026-3519 Published : 20. April 2026 14:16 | 1 Stunde, 10 Minuten ago Description :OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-33558 - Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output

CVE ID :CVE-2026-33558 Published : 20. April 2026 14:16 | 1 Stunde, 10 Minuten ago Description :Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the requests and responses output log. The entire lists of impacted requests and responses are: * AlterConfigsRequest * AlterUserScramCredentialsRequest * ExpireDelegationTokenRequest * IncrementalAlterConfigsRequest * RenewDelegationTokenRequest * SaslAuthenticateRequest * createDelegationTokenResponse * describeDelegationTokenResponse * SaslAuthenticateResponse This issue affects Apache Kafka: from any version supported the listed API above through v3.9.1, v4.0.0. We advise the Kafka users to upgrade to v3.9.2, v4.0.1, or later to avoid this vulnerability. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-33557 - Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication

CVE ID :CVE-2026-33557 Published : 20. April 2026 14:16 | 1 Stunde, 10 Minuten ago Description :A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An attacker can generate a JWT token from any issuer with the `preferred_username` set to any user, and the broker will accept it. We advise the Kafka users using kafka v4.1.0 or v4.1.1 to set the config `sasl.oauthbearer.jwt.validator.class` to `org.apache.kafka.common.security.oauthbearer.BrokerJwtValidator` explicitly to avoid this vulnerability. Since Kafka v4.1.2 and v4.2.0 and later, the issue is fixed and will correctly validate the JWT token. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2025-66335 - Apache Doris MCP Server: MCP SQL inject

CVE ID :CVE-2025-66335 Published : 20. April 2026 14:16 | 1 Stunde, 11 Minuten ago Description :Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-34428 - Vvveb < 1.0.8.1 SSRF via oEmbedProxy

CVE ID :CVE-2026-34428 Published : 20. April 2026 13:55 | 1 Stunde, 31 Minuten ago Description :Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor module where the url parameter is passed directly to getUrl() via curl without scheme or destination validation. Authenticated backend users can supply file:// URLs to read arbitrary files readable by the web server process or http:// URLs targeting internal network addresses to probe internal services, with response bodies returned directly to the caller. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-34427 - Vvveb < 1.0.8.1 Privilege Escalation via admin/user/save

CVE ID :CVE-2026-34427 Published : 20. April 2026 13:55 | 1 Stunde, 32 Minuten ago Description :Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileged fields on their own profile. Attackers can inject role_id=1 into profile save requests to escalate to Super Administrator privileges, enabling plugin upload functionality for remote code execution. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-34429 - Vvveb < 1.0.8.1 Stored XSS via Media Upload and Rename

CVE ID :CVE-2026-34429 Published : April 20, 2026, 4:16 p.m. | 1 hour, 11 minutes ago Description :Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media upload and rename permissions to execute arbitrary JavaScript by bypassing MIME type validation and renaming uploaded files to executable extensions. Attackers can prepend a GIF89a header to HTML/JavaScript payloads to bypass upload validation, rename the file to .html extension, and execute malicious scripts in an administrator's browser session to create backdoor accounts and upload malicious plugins for remote code execution. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
News
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More

⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser ex ... Read more Published Date: Apr 20, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom20 apr 2026
News
Public PoC and Technical Details Disclosed for Apache Syncope RCE

Public PoC and Technical Details Disclosed for Apache Syncope RCE A new report from SecureLayer7 has unmasked a high-severity Remote Code Execution (RCE) vulnerability in Apache Syncope, a cornerstone of identity lifecycle management and access governance in many en ... Read more Published Date: Apr 20, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-23500 CVE-2026-20147 CVE-2026-22679 CVE-2026-20160 CVE-2026-34156 CVE-2025-57738

CVEfeed Newsroom20 apr 2026
News
Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE

Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE A security vulnerability has been identified in Dolibarr ERP & CRM, a popular open-source suite used by organizations worldwide to manage business activities ranging from invoices to human resources. ... Read more Published Date: Apr 20, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-23500 CVE-2026-35337 CVE-2026-22679 CVE-2025-57738

CVEfeed Newsroom20 apr 2026
VulnerabilitàAlta
CVE-2026-6648 - Qibo CMS Internal Message cross site scripting

CVE ID :CVE-2026-6648 Published : 20. April 2026 13:16 | 2 Stunden, 11 Minuten ago Description :A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component Internal Message Module. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026

Pagina 2180 di 3196

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.