Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38517 risultati

VulnerabilitàAlta
CVE-2026-35153 - Dell PowerProtect Data Domain Argument Injection Vulnerability

CVE ID :CVE-2026-35153 Published : April 17, 2026, 11:16 a.m. | 2 hours, 42 minutes ago Description :Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-35072 - Dell PowerProtect Data Domain OS Command Injection

CVE ID :CVE-2026-35072 Published : April 17, 2026, 11:16 a.m. | 2 hours, 42 minutes ago Description :Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command ('OS command injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-35073 - Dell PowerProtect Data Domain OS Command Injection Vulnerability

CVE ID :CVE-2026-35073 Published : April 17, 2026, 11:16 a.m. | 2 hours, 42 minutes ago Description :Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-35074 - Dell PowerProtect Data Domain OS Command Injection

CVE ID :CVE-2026-35074 Published : April 17, 2026, 11:16 a.m. | 2 hours, 42 minutes ago Description :Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2025-46607 - Dell PowerProtect Data Domain DD OS Improper Authentication Vulnerability

CVE ID :CVE-2025-46607 Published : April 17, 2026, 12:16 p.m. | 3 hours, 42 minutes ago Description :Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. Severity: 6.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
News
Vulnerability in GREENmod software

Vulnerability in GREENmod software Vulnerability in GREENmod software CVE ID CVE-2026-5131 Publication date 17 April 2026 Vendor Nomios Poland Product GREENmod Vulnerable versions All before 2.8.33 Vulnerability type (CWE) Server-Side ... Read more Published Date: Apr 17, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5131

CVEfeed Newsroom17 apr 2026
News
CISA Warns of Apache ActiveMQ Input Validation Vulnerability Exploited in Attacks

CISA Warns of Apache ActiveMQ Input Validation Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security defect in Apache ActiveMQ. On April 16, 2026, the agency officially added the vul ... Read more Published Date: Apr 17, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197

CVEfeed Newsroom17 apr 2026
News
Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks

Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks An active in-the-wild exploitation of three recently leaked Windows Defender privilege escalation vulnerabilities, with threat actors deploying proof-of-concept exploit code sourced directly from publ ... Read more Published Date: Apr 17, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33825

CVEfeed Newsroom17 apr 2026
News
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild

Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild The security researcher who earlier this month published a proof-of-concept (PoC) exploit for a zero-day privilege escalation vulnerability in Microsoft Defender is back with two more. The first, dubb ... Read more Published Date: Apr 17, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33825 CVE-2026-39813 CVE-2026-39808

CVEfeed Newsroom17 apr 2026
VulnerabilitàAlta
CVE-2026-6439 - VideoZen <= 1.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'VideoZen available subtitles languages' Field

CVE ID :CVE-2026-6439 Published : April 17, 2026, 9:16 a.m. | 4 hours, 42 minutes ago Description :The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. This is due to insufficient input sanitization and output escaping in the videozen_conf() function. The 'lang' POST parameter is stored directly via update_option() without any sanitization, and later echoed inside a element without applying esc_textarea() or any equivalent escaping function. This makes it possible for authenticated attackers with Administrator-level access and above to inject arbitrary web scripts into the plugin settings page that will execute whenever any user accesses that page. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-23778 - Dell PowerProtect Data Domain DDOS Command Injection Vulnerability

CVE ID :CVE-2026-23778 Published : April 17, 2026, 9:16 a.m. | 4 hours, 42 minutes ago Description :Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to gain root-level access. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026
VulnerabilitàAlta
CVE-2026-23775 - "Dell PowerProtect Data Domain DD OS Sensitive Information Log Injection Vulnerability"

CVE ID :CVE-2026-23775 Published : April 17, 2026, 9:16 a.m. | 2 hours, 42 minutes ago Description :Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to credential exposures. Authentication attempts as the compromised user would need to be authorized by a high privileged DD user. This vulnerability only affects systems with retention lock enabled. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 apr 2026

Pagina 2221 di 3210

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.