Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38505 risultati

VulnerabilitàAlta
CVE-2026-6597 - langflow-ai langflow Flow Using API core.py has_api_terms credentials storage

CVE ID :CVE-2026-6597 Published : April 20, 2026, 3:16 a.m. | 2 hours, 9 minutes ago Description :A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
News
Root Access Unlocked: FortiSandbox CVE-2026-39808 Details and PoC Exploit Publicly Disclosed

Root Access Unlocked: FortiSandbox CVE-2026-39808 Details and PoC Exploit Publicly Disclosed Image: Samuel de Lucas Maroto A critical vulnerability in FortiSandbox has been disclosured. The flaw, tracked as CVE-2026-39808, carries a devastating CVSS score of 9.1, allowing unauthenticated atta ... Read more Published Date: Apr 20, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20147 CVE-2026-39813 CVE-2026-39808 CVE-2026-22679 CVE-2026-27728

CVEfeed Newsroom20 apr 2026
VulnerabilitàAlta
CVE-2026-6594 (CVSS 7.3)

A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)20 apr 2026
VulnerabilitàAlta
CVE-2026-6593 - ComfyUI View Endpoint server.py cross site scripting

CVE ID :CVE-2026-6593 Published : April 20, 2026, 2:16 a.m. | 1 hour, 9 minutes ago Description :A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6594 - brikcss merge prototype pollution

CVE ID :CVE-2026-6594 Published : April 20, 2026, 2:16 a.m. | 3 hours, 9 minutes ago Description :A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6592 - ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting

CVE ID :CVE-2026-6592 Published : April 20, 2026, 2:16 a.m. | 1 hour, 9 minutes ago Description :A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
News
The CVE Watchtower: Weekly Threat Intelligence Briefing (April 13 – April 19, 2026)

The CVE Watchtower: Weekly Threat Intelligence Briefing (April 13 – April 19, 2026) Welcome to this week’s vulnerability digest. Between April 13 and April 19, 2026, the global security community logged 1,214 newly published vulnerabilities. Whether you are a CISO evaluating AI risk ... Read more Published Date: Apr 20, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom20 apr 2026
VulnerabilitàAlta
CVE-2026-6591 - ComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal

CVE ID :CVE-2026-6591 Published : April 20, 2026, 1:16 a.m. | 2 hours, 9 minutes ago Description :A flaw has been found in ComfyUI up to 0.13.0. Affected is the function folder_paths.get_annotated_filepath of the file folder_paths.py of the component LoadImage Node. This manipulation of the argument Name causes path traversal. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6590 - ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal

CVE ID :CVE-2026-6590 Published : April 20, 2026, 1:16 a.m. | 2 hours, 9 minutes ago Description :A vulnerability was detected in ComfyUI up to 0.13.0. This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpoint. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6589 - ComfyUI server.py create_origin_only_middleware cross-site request forgery

CVE ID :CVE-2026-6589 Published : April 20, 2026, 1:16 a.m. | 2 hours, 9 minutes ago Description :A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6585 - TransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation authorization

CVE ID :CVE-2026-6585 Published : April 20, 2026, 12:16 a.m. | 3 hours, 9 minutes ago Description :A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/controllers/organisation.py of the component Organisation Update Endpoint. This manipulation of the argument organisation_id causes authorization bypass. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6587 - vibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery

CVE ID :CVE-2026-6587 Published : April 20, 2026, 12:16 a.m. | 3 hours, 9 minutes ago Description :A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argument retrieved_contexts results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The security patch for CVE-2025-45691 was applied to a different module only. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026

Pagina 2202 di 3209

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.