Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38490 risultati

VulnerabilitàAlta
CVE-2026-6601 - Lagom WHMCS Template Datatables resource consumption

CVE ID :CVE-2026-6601 Published : April 20, 2026, 4:16 a.m. | 3 hours, 9 minutes ago Description :A vulnerability has been found in Lagom WHMCS Template up to 2.4.2. This impacts an unknown function of the component Datatables. The manipulation leads to resource consumption. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6600 - langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting

CVE ID :CVE-2026-6600 Published : April 20, 2026, 4:16 a.m. | 3 hours, 9 minutes ago Description :A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of the component Frontend React Component Rendering. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6599 - langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection

CVE ID :CVE-2026-6599 Published : April 20, 2026, 4:16 a.m. | 3 hours, 9 minutes ago Description :A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function get_client_ip/install_mcp_config of the file src/backend/base/langflow/api/v1/mcp_projects.py of the component Model Context Protocol Configuration API. Performing a manipulation of the argument X-Forwarded-For results in injection. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6598 - langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file

CVE ID :CVE-2026-6598 Published : April 20, 2026, 4:16 a.m. | 3 hours, 9 minutes ago Description :A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflow/api/v1/projects.py of the component Project Creation Endpoint. Such manipulation of the argument auth_settings leads to cleartext storage in a file or on disk. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-32965 - Silex SD-330AC and AMC Manager Default Password Vulnerability

CVE ID :CVE-2026-32965 Published : April 20, 2026, 4:16 a.m. | 3 hours, 9 minutes ago Description :Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the initial (factory-default) configuration, the device can be configured with the null string password. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-32964 - Silex Technology, Inc. SD-330AC and AMC Manager CRLF Injection

CVE ID :CVE-2026-32964 Published : April 20, 2026, 4:16 a.m. | 3 hours, 9 minutes ago Description :SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-32963 - Silex Technology, Inc. SD-330AC and AMC Manager Reflected Cross-Site Scripting

CVE ID :CVE-2026-32963 Published : April 20, 2026, 4:16 a.m. | 3 hours, 9 minutes ago Description :SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-32962 - Silex SD-330AC and AMC Manager Unauthenticated Configuration Alteration Vulnerability

CVE ID :CVE-2026-32962 Published : April 20, 2026, 4:16 a.m. | 3 hours, 9 minutes ago Description :SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-32960 - Silex Technology, Inc. SD-330AC and AMC Manager Password Bypass

CVE ID :CVE-2026-32960 Published : April 20, 2026, 4:16 a.m. | 1 hour, 9 minutes ago Description :SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing the password by sending a crafted packet. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-32961 - Silex SD-330AC and AMC Manager Heap-Based Buffer Overflow Vulnerability

CVE ID :CVE-2026-32961 Published : April 20, 2026, 4:16 a.m. | 3 hours, 9 minutes ago Description :SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-32959 - Silex Technology, Inc. SD-330AC and AMC Manager Weak Cryptography Vulnerability

CVE ID :CVE-2026-32959 Published : April 20, 2026, 4:16 a.m. | 1 hour, 9 minutes ago Description :SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle attack. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-32958 - Silex SD-330AC and AMC Manager Cryptographic Key Hard-Coded Vulnerability

CVE ID :CVE-2026-32958 Published : April 20, 2026, 4:16 a.m. | 1 hour, 9 minutes ago Description :SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026

Pagina 2199 di 3208

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.