Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38490 risultati

VulnerabilitàAlta
CVE-2026-6632 - Tenda F451 httpd SafeClientFilter fromSafeClientFilter buffer overflow

CVE ID :CVE-2026-6632 Published : April 20, 2026, 11:16 a.m. | 2 hours, 10 minutes ago Description :A vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. The affected element is the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6631 - Tenda F451 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow

CVE ID :CVE-2026-6631 Published : April 20, 2026, 11:16 a.m. | 2 hours, 10 minutes ago Description :A vulnerability was determined in Tenda F451 1.0.0.7_cn_svn7958. Impacted is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. Executing a manipulation of the argument page can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6630 - Tenda F451 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow

CVE ID :CVE-2026-6630 Published : April 20, 2026, 11:16 a.m. | 2 hours, 10 minutes ago Description :A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. Performing a manipulation of the argument dips results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6629 (CVSS 7.3)

A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file sql.jsp of the component Interface. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)20 apr 2026
VulnerabilitàAlta
CVE-2026-6629 - Metasoft 美特软件 MetaCRM Interface sql.jsp Statement.executeUpdate sql injection

CVE ID :CVE-2026-6629 Published : April 20, 2026, 11:16 a.m. | 2 hours, 10 minutes ago Description :A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file sql.jsp of the component Interface. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
News
Vulnerability in GNU sed software

Vulnerability in GNU sed software Vulnerability in GNU sed software CVE ID CVE-2026-5958 Publication date 20 April 2026 Vendor GNU Product sed Vulnerable versions From 4.1e below 4.10 Vulnerability type (CWE) Time-of-check Time-of-use ... Read more Published Date: Apr 20, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5958

CVEfeed Newsroom20 apr 2026
News
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain

Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain Cybersecurity researchers have discovered a critical "by design" weakness in the Model Context Protocol's (MCP) architecture that could pave the way for remote code execution and have a cascading effe ... Read more Published Date: Apr 20, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom20 apr 2026
News
Aanvallen op end-of-life TP-Link routers via oude kwetsbaarheid

Aanvallen op end-of-life TP-Link routers via oude kwetsbaarheid TP-Link-routers worden actief aangevallen via een kwetsbaarheid uit 2023, zo stelt securitybedrijf Palo Alto Networks. Het gaat om end-of-life modellen van TP-Link waarvoor geen updates meer beschikb ... Read more Published Date: Apr 20, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2023-33538

CVEfeed Newsroom20 apr 2026
VulnerabilitàAlta
CVE-2026-6628 - phili67 Ecclesia CRM Query Viewer view ValidateInput sql injection

CVE ID :CVE-2026-6628 Published : April 20, 2026, 10:16 a.m. | 3 hours, 10 minutes ago Description :A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query Viewer Component. This manipulation of the argument custom causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6625 (CVSS 7.3)

A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)20 apr 2026
VulnerabilitàAlta
CVE-2026-6625 - moxi624 Mogu Blog v2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadPictureByUrl server-side request forgery

CVE ID :CVE-2026-6625 Published : April 20, 2026, 10:16 a.m. | 3 hours, 10 minutes ago Description :A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6626 - Cockpit-HQ Cockpit Asset Handler/Aggregate data query logic injection

CVE ID :CVE-2026-6626 Published : April 20, 2026, 10:16 a.m. | 3 hours, 10 minutes ago Description :A vulnerability was detected in Cockpit-HQ Cockpit up to 2.13.5. Affected by this issue is some unknown functionality of the component Asset Handler/Aggregate Handler. The manipulation results in improper neutralization of special elements in data query logic. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026

Pagina 2194 di 3208

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.