News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38556 risultati
CVE ID :CVE-2026-40505 Published : April 16, 2026, 2:16 a.m. | 1 hour, 41 minutes ago Description :MuPDF mutool does not sanitize PDF metadata fields before writing them to terminal output, allowing attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to the terminal when running mutool info, enabling them to clear the terminal display and render arbitrary text for social engineering attacks such as presenting fake prompts or spoofed commands. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
RedSun: New Windows Defender Zero-Day Turns Protector into Attacker, PoC Publishes Just as the cybersecurity community began digesting the latest round of patches for the high-profile “BlueHammer” vulnerability, a new storm has appeared on the horizon. On April 16, 2026, the securit ... Read more Published Date: Apr 16, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-20184 CVE-2026-20180 CVE-2026-33825 CVE-2026-22679 CVE-2026-33032 CVE-2026-21962
Critical 9.8 Webex Flaw Lets Attackers Impersonate Any User In the modern enterprise, the Single Sign-On (SSO) portal is the master key to a company’s digital life. However, a recently disclosed critical vulnerability in Cisco Webex Services has revealed how a ... Read more Published Date: Apr 16, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-20184 CVE-2026-20204 CVE-2026-32201 CVE-2026-22679
Splunk Issues Urgent Fixes for RCE and Clear-Text Token Leaks Splunk has released a series of security advisories detailing two significant vulnerabilities impacting Splunk Enterprise, Splunk Cloud Platform, and the Splunk MCP Server app. These flaws could allow ... Read more Published Date: Apr 16, 2026 (23 hours, 10 minutes ago) Vulnerabilities has been mentioned in this article.
Chrome 147 Update: Google Patches Critical $90,000 ANGLE Flaw and 30 Other Security Gaps Google has begun rolling out a high-stakes update for the Chrome stable channel, addressing a total of 31 security vulnerabilities, including five rated as Critical. The release, version 147.0.7727.10 ... Read more Published Date: Apr 16, 2026 (21 hours, 22 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-6364 CVE-2026-6358 CVE-2026-6307 CVE-2026-6301 CVE-2026-6299 CVE-2026-6298 CVE-2026-6297 CVE-2026-6296 CVE-2026-20147 CVE-2026-20204 CVE-2026-32201 CVE-2026-22679 CVE-2025-6558
Root Access via Admin: The 9.9 RCE Crisis Threatening Cisco ISE Networks Cisco has issued an urgent security advisory following the discovery of high-stakes vulnerabilities in its Identity Services Engine (ISE) and Passive Identity Connector (ISE-PIC) platforms. The most s ... Read more Published Date: Apr 16, 2026 (15 hours, 26 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-6296 CVE-2026-20148 CVE-2026-20147 CVE-2026-32201 CVE-2026-4631 CVE-2026-22679 CVE-2026-20045
OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execute administrative commands such as /permissions full_auto through remote chat sessions to change permission modes of a running OpenHarness instance without operator authorization.
CVE ID :CVE-2026-40959 Published : April 16, 2026, 1:16 a.m. | 2 hours, 41 minutes ago Description :Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40502 Published : April 16, 2026, 1:16 a.m. | 2 hours, 41 minutes ago Description :OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execute administrative commands such as /permissions full_auto through remote chat sessions to change permission modes of a running OpenHarness instance without operator authorization. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40503 Published : April 16, 2026, 1:16 a.m. | 2 hours, 41 minutes ago Description :OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate the path input parameter to escape the project memory directory and access sensitive files accessible to the OpenHarness process without filesystem containment validation. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40960 Published : April 16, 2026, 1:16 a.m. | 2 hours, 41 minutes ago Description :Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Base64-encoded user ID in the token parameter to identify users, leaking valid authentication tokens through the 'barcodeScannerConfigs' action, and lacking meta-key restrictions on the 'setUserMeta' action. This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator by first spoofing the admin user ID to leak their authentication token, then using that token to update any user's 'wp_capabilities' meta to gain full administrative access.
Pagina 2243 di 3213