News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38523 risultati
CVE ID :CVE-2026-23779 Published : April 17, 2026, 10:16 a.m. | 3 hours, 42 minutes ago Description :Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain root-level access. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-23776 Published : April 17, 2026, 10:16 a.m. | 3 hours, 42 minutes ago Description :Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain(s) an Improper Certificate Validation vulnerability in certificate-based login. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches Microsoft has confirmed a critical known issue affecting Windows Server 2025 domain controllers following the deployment of the April 2026 Patch Tuesday cumulative update, KB5082063, where affected se ... Read more Published Date: Apr 17, 2026 (2 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20833 CVE-2026-0386
Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerabili ... Read more Published Date: Apr 17, 2026 (2 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33829
Critical nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover A critical vulnerability identified as CVE-2026-33032 is drawing urgent attention from the cybersecurity community due to its role in enabling a full-scale Nginx server takeover. The flaw affects ngin ... Read more Published Date: Apr 17, 2026 (2 days, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33032 CVE-2026-27944
One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly ... Read more Published Date: Apr 17, 2026 (2 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-32196
CVE ID :CVE-2026-40002 Published : April 17, 2026, 8:16 a.m. | 3 hours, 42 minutes ago Description :Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific partitions and set writable system properties. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6451 Published : April 17, 2026, 8:16 a.m. | 3 hours, 42 minutes ago Description :The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation on all eight AJAX deletion handlers: vehicles_cfmw_d_vehicle, contacts_cfmw_d_contact, suppliers_cfmw_d_supplier, receipts_cfmw_d_receipt, positions_cfmw_d_position, catalogs_cfmw_d_article, stock_cfmw_d_item, and settings_cfmw_d_catalog. None of these handlers call check_ajax_referer() or wp_verify_nonce(), nor do they perform any capability checks via current_user_can(). This makes it possible for unauthenticated attackers to delete arbitrary vehicles, contacts, suppliers, receipts, positions, catalog articles, stock items, or entire supplier catalogs via a forged request, provided they can trick a logged-in user into performing an action such as clicking a link to a malicious page. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-33392 Published : April 17, 2026, 8:16 a.m. | 3 hours, 42 minutes ago Description :In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical Pre-Auth RCE Found in OpenAM Identity Platform OpenAM, the widely-deployed open-source access management solution, is facing a critical security challenge following the discovery of a pre-authentication Remote Code Execution (RCE) vulnerability. T ... Read more Published Date: Apr 17, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-6264 CVE-2026-33439 CVE-2026-22679 CVE-2026-0740 CVE-2026-33701 CVE-2021-35464
CVE ID :CVE-2026-23853 Published : April 17, 2026, 8:16 a.m. | 3 hours, 42 minutes ago Description :Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a use of weak credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to the system. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.
Pagina 2223 di 3211