Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38490 risultati

VulnerabilitàAlta
CVE-2026-6619 - langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting

CVE ID :CVE-2026-6619 Published : April 20, 2026, 9:16 a.m. | 4 hours, 10 minutes ago Description :A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePreview. The manipulation of the argument filename leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
News
Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware

Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware A newly identified botnet campaign is actively exploiting a critical flaw in TBK digital video recorders to deploy a dangerous piece of malware known as Nexcorium, a Mirai-based threat built to launch ... Read more Published Date: Apr 20, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-3721 CVE-2017-17215

CVEfeed Newsroom20 apr 2026
VulnerabilitàAlta
CVE-2026-6618 - langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery

CVE ID :CVE-2026-6618 Published : April 20, 2026, 9:16 a.m. | 4 hours, 10 minutes ago Description :A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
News
Fabricked: The 100% Deterministic Attack Breaking AMD’s Confidential Computing Vault

Fabricked: The 100% Deterministic Attack Breaking AMD’s Confidential Computing Vault Schematic overview of the Infinity Fabric In the high-stakes world of cloud security, the promise of Confidential Computing is simple: your data should be safe even from the person owning the server. ... Read more Published Date: Apr 20, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-54510 CVE-2026-22679 CVE-2025-0033

CVEfeed Newsroom20 apr 2026
VulnerabilitàAlta
CVE-2026-6644 - A command injection vulnerability was found in the PPTP VPN Clients on the ADM

CVE ID :CVE-2026-6644 Published : April 20, 2026, 7:16 a.m. | 2 hours, 10 minutes ago Description :A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied input before it is passed to a system shell. Successful exploitation allows an attacker to achieve Remote Code Execution (RCE) and fully compromise the system. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6614 - TransformerOptimus SuperAGI project.py get_projects_organisation authorization

CVE ID :CVE-2026-6614 Published : April 20, 2026, 7:16 a.m. | 2 hours, 10 minutes ago Description :A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_organisation of the file superagi/controllers/project.py. The manipulation results in authorization bypass. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6643 - A stack-based buffer overflow vulnerability in the VPN Clients on the ADM

CVE ID :CVE-2026-6643 Published : April 20, 2026, 7:16 a.m. | 2 hours, 10 minutes ago Description :A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an authenticated remote attacker can exploit these to execute arbitrary code as the web server user. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6613 - TransformerOptimus SuperAGI agent.py get_schedule_data authorization

CVE ID :CVE-2026-6613 Published : April 20, 2026, 7:16 a.m. | 2 hours, 10 minutes ago Description :A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of the file superagi/controllers/agent.py. The manipulation of the argument agent_id leads to authorization bypass. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6610 - liangliangyy DjangoBlog Setting settings.py hard-coded credentials

CVE ID :CVE-2026-6610 Published : April 20, 2026, 6:16 a.m. | 3 hours, 10 minutes ago Description :A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipulation of the argument USER/PASSWORD leads to hard-coded credentials. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6609 - liangliangyy DjangoBlog views.py form_valid improper authorization

CVE ID :CVE-2026-6609 Published : April 20, 2026, 6:16 a.m. | 3 hours, 10 minutes ago Description :A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This manipulation of the argument oauthid causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6608 - lm-sys fastchat Arena Side-by-Side View add_text control flow

CVE ID :CVE-2026-6608 Published : April 20, 2026, 6:16 a.m. | 3 hours, 10 minutes ago Description :A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The exploit is now public and may be used. The root cause was fixed in commit 34eca62 for gradio_block_arena_named.py, but three other files were missed. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6612 - TransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution authorization

CVE ID :CVE-2026-6612 Published : April 20, 2026, 7:16 a.m. | 2 hours, 10 minutes ago Description :A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of the file superagi/controllers/agent_execution.py of the component Agent Execution Endpoint. Executing a manipulation of the argument agent_execution_id can lead to authorization bypass. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026

Pagina 2197 di 3208

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.