Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38523 risultati

VulnerabilitàAlta
CVE-2026-33082 - DataEase: SQL Injection in v2 Dataset Export

CVE ID :CVE-2026-33082 Published : April 16, 2026, 6:16 p.m. | 3 hours, 41 minutes ago Description :DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST /de2api/datasetTree/exportDataset is deserialized into a filtering object and passed to WhereTree2Str.transFilterTrees for SQL translation, where user-controlled values in "like" filter terms are directly concatenated into SQL fragments without sanitization. An attacker can inject arbitrary SQL commands by escaping the string literal in the filter value, enabling blind SQL injection through techniques such as time-based extraction of database information. This issue has been fixed in version 2.10.21. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-33083 - DataEase has SQL Injection in Order By Clause

CVE ID :CVE-2026-33083 Published : April 16, 2026, 6:16 p.m. | 3 hours, 41 minutes ago Description :DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoints including /de2api/datasetData/enumValueDs and /de2api/datasetTree/exportDataset. The Order2SQLObj class directly assigns the raw user-supplied orderDirection value into the SQL query without any validation or whitelist enforcement, and the value is rendered into the ORDER BY clause via StringTemplate before being executed against the database. An authenticated attacker can inject arbitrary SQL commands through the sorting direction field, enabling time-based blind data extraction and denial of service. This issue has been fixed in version 2.10.21. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-27820 - zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption

CVE ID :CVE-2026-27820 Published : April 16, 2026, 6:16 p.m. | 3 hours, 41 minutes ago Description :zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. This issue has been fixed in versions 3.0.1, 3.1.2 and 3.2.3. Severity: 1.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2025-43883 - Dell PowerScale OneFS Denial of Service Vulnerability

CVE ID :CVE-2025-43883 Published : April 16, 2026, 6:16 p.m. | 3 hours, 41 minutes ago Description :Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2025-36579 - Dell Client Platform BIOS Authentication Bypass

CVE ID :CVE-2025-36579 Published : April 16, 2026, 5:16 p.m. | 2 hours, 41 minutes ago Description :Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-41080 - Oracle libexpat Hash Flooding Vulnerability

CVE ID :CVE-2026-41080 Published : April 16, 2026, 5:16 p.m. | 4 hours, 41 minutes ago Description :libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. Severity: 2.9 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-24749 - Silverstripe Assets Module has a DBFile::getURL() permission bypass

CVE ID :CVE-2026-24749 Published : April 16, 2026, 6:16 p.m. | 3 hours, 41 minutes ago Description :The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file permissions. This usually happens when creating an image variant, for example using a manipulation method like ScaleWidth() or Convert(). Note that if developers use DBFile directly in the $db configuration for a DataObject class that doesn't subclass File, and if they were setting the visibility of those files to "protected", those files will now need an explicit access grant to be accessed. If developers do not want to explicitly provide access grants for these files in their apps (i.e. they want these files to be accessible by default), they should use the "public" visibility. This issue has been fixed in versions 2.4.5 and 3.1.3. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-2336 - Weak webstax_auth Cookie Authentication Allows Privilege Escalation

CVE ID :CVE-2026-2336 Published : April 16, 2026, 6:16 p.m. | 3 hours, 41 minutes ago Description :A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-5426 - KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey value

CVE ID :CVE-2026-5426 Published : April 16, 2026, 4:16 p.m. | 3 hours, 42 minutes ago Description :Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-37100 - Yamaha SR-B30A BLE Authentication Bypass Vulnerability

CVE ID :CVE-2026-37100 Published : April 16, 2026, 4:16 p.m. | 3 hours, 42 minutes ago Description :An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio range to connect without authentication via the Sound Bar Remote protocol Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
News
Fortinet FortiSandbox — Critical Vulnerability Advisory

Fortinet FortiSandbox — Critical Vulnerability Advisory April 16, 2026Fortinet published a sweeping security advisory on April 14, 2026, disclosing multiple vulnerabilities across its FortiSandbox platform. Two of the flaws are rated Critical with unauthen ... Read more Published Date: Apr 16, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-39813 CVE-2026-39808 CVE-2026-27316 CVE-2026-25691 CVE-2026-34621 CVE-2026-25836 CVE-2026-21643

CVEfeed Newsroom16 apr 2026
VulnerabilitàAlta
CVE-2026-6409 - Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input

CVE ID :CVE-2026-6409 Published : April 16, 2026, 3:17 p.m. | 4 hours, 40 minutes ago Description :A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or deep recursion—can be used to crash the application, impacting service availability. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026

Pagina 2230 di 3211

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.