Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38517 risultati

News
Vulnerabilities in PAC4J software

Vulnerabilities in PAC4J software Vulnerabilities in PAC4J software CVE ID CVE-2026-40458 Publication date 17 April 2026 Vendor PAC4J Product PAC4J Vulnerable versions From 5.0 to 5.7.10 From 6.0 to 6.4.1 Vulnerability type (CWE) Cros ... Read more Published Date: Apr 17, 2026 (3 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-40459 CVE-2026-40458

CVEfeed Newsroom17 apr 2026
News
Micropatches released for Windows Error Reporting Service Elevation of Privilege Vulnerability (CVE-2026-20817)

Micropatches released for Windows Error Reporting Service Elevation of Privilege Vulnerability (CVE-2026-20817) January 2026 Windows Updates brought a patch for CVE-2026-20817, a local privilege elevation vulnerability in Windows Error Reporting Service, allowing a local non-admin attacker to execute arbitrary ... Read more Published Date: Apr 17, 2026 (3 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-20817

CVEfeed Newsroom17 apr 2026
News
Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine

Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine Thymeleaf, a widely-used modern server-side Java template engine for both web and standalone environments, has released a critical security update. The update addresses two high-severity vulnerabiliti ... Read more Published Date: Apr 17, 2026 (3 days, 1 hour ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom17 apr 2026
News
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched Huntress is warning that threat actors are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges in compromised systems. The activity involves the exploi ... Read more Published Date: Apr 17, 2026 (3 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-33825 CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2025-55182

CVEfeed Newsroom17 apr 2026
VulnerabilitàAlta
CVE-2026-40459 - LDAP Injection in PAC4J

CVE ID :CVE-2026-40459 Published : April 17, 2026, 2:16 p.m. | 3 hours, 42 minutes ago Description :PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations. This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1 Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-40458 - Cross-Site Request Forgery in PAC4J

CVE ID :CVE-2026-40458 Published : April 17, 2026, 2:16 p.m. | 3 hours, 42 minutes ago Description :PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automatically submit a forged cross-site request with a token whose hash collides with the victim's legitimate CSRF token. Importantly, the attacker does not need to know the victim’s CSRF token or its hash prior to the attack. Collisions in the deterministic String.hashCode() function can be computed directly, reducing the effective token's security space to 32 bits. This bypasses CSRF protection, allowing profile updates, password changes, account linking, and any other state-changing operations to be performed without the victim's consent. This issue was fixed in PAC4J versions 5.7.10 and 6.4.1 Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-6507 (CVSS 7.5)

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).

NVD (NIST)17 apr 2026
VulnerabilitàAlta
CVE-2026-6489 - QueryMine sms Background Management addteacher.php unrestricted upload

CVE ID :CVE-2026-6489 Published : April 17, 2026, 1:16 p.m. | 4 hours, 42 minutes ago Description :A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component Background Management Page. The manipulation of the argument image results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-6486 - classroombookings User Display Name layout.php read cross site scripting

CVE ID :CVE-2026-6486 Published : April 17, 2026, 1:16 p.m. | 4 hours, 42 minutes ago Description :A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 2.17.1 will fix this issue. The patch is identified as 69c3c9bb8a17f1ea572d8f4502bf238f0214c98a. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-6488 - QueryMine sms GET Request Parameter editcourse.php sql injection

CVE ID :CVE-2026-6488 Published : April 17, 2026, 1:16 p.m. | 4 hours, 42 minutes ago Description :A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affects unknown code of the file admin/editcourse.php of the component GET Request Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-6507 - Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing

CVE ID :CVE-2026-6507 Published : April 17, 2026, 1:16 p.m. | 4 hours, 42 minutes ago Description :A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS). Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-6487 - Qihui jtbc5 CMS Code Endpoint manage.php path traversal

CVE ID :CVE-2026-6487 Published : April 17, 2026, 1:16 p.m. | 4 hours, 42 minutes ago Description :A flaw has been found in Qihui jtbc5 CMS 5.0.3.6. Affected is an unknown function of the file /dev/code/common/diplomat/manage.php of the component Code Endpoint. This manipulation of the argument path causes path traversal. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026

Pagina 2219 di 3210

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.