Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38556 risultati

VulnerabilitàAlta
CVE-2026-6384 - Gimp: gimp: arbitrary code execution or denial of service via buffer overflow in gif image processing

CVE ID :CVE-2026-6384 Published : April 15, 2026, 8:16 p.m. | 3 hours, 41 minutes ago Description :A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-6364 - Google Chrome Skia Out-of-Bounds Read

CVE ID :CVE-2026-6364 Published : April 15, 2026, 8:16 p.m. | 3 hours, 41 minutes ago Description :Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security severity: Medium) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-6319 - Google Chrome Android Use-After-Free RCE

CVE ID :CVE-2026-6319 Published : April 15, 2026, 8:16 p.m. | 1 hour, 41 minutes ago Description :Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-6318 - Google Chrome Codecs Use After Free Vulnerability

CVE ID :CVE-2026-6318 Published : April 15, 2026, 8:16 p.m. | 1 hour, 41 minutes ago Description :Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-6362 - Google Chrome Use After Free in Codecs Vulnerability

CVE ID :CVE-2026-6362 Published : April 15, 2026, 8:16 p.m. | 3 hours, 41 minutes ago Description :Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: High) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-6317 - Google Chrome Use After Free Remote Code Execution Vulnerability

CVE ID :CVE-2026-6317 Published : April 15, 2026, 8:16 p.m. | 1 hour, 41 minutes ago Description :Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-6363 - Google Chrome V8 Type Confusion Memory Access

CVE ID :CVE-2026-6363 Published : April 15, 2026, 8:16 p.m. | 3 hours, 41 minutes ago Description :Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-6361 - Google Chrome PDFium Heap Buffer Overflow

CVE ID :CVE-2026-6361 Published : April 15, 2026, 8:16 p.m. | 3 hours, 41 minutes ago Description :Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
News
Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP

Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP Watch out for more Fortinet vulns! Two critical bugs in Fortinet's sandbox could allow unauthenticated attackers to bypass authentication or execute unauthorized code on vulnerable systems. Luckily, t ... Read more Published Date: Apr 15, 2026 (21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-39813 CVE-2026-39808 CVE-2026-35616

CVEfeed Newsroom15 apr 2026
VulnerabilitàAlta
CVE-2026-6290 - Velociraptor Query() Plugin Misapplies Permissions To Orgs

CVE ID :CVE-2026-6290 Published : April 15, 2026, 5:29 p.m. | 28 minutes ago Description :Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which they may not have access to. The user's permissions in the other org are the same as the permissions they have in the org containing the notebook. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-32631 - Git for Windows: `git clone` from manipulated repositories can leak NTLM hashes to arbitrary servers

CVE ID :CVE-2026-32631 Published : April 15, 2026, 5:26 p.m. | 31 minutes ago Description :Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. By brute-forcing the NTLMv2 hash (which is expensive, but possible), credentials can be extracted. This issue has been fixed in version 2.53.0.windows.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-5758 - Mafintosh's protocol-buffers-schema is vulnerable to prototype pollution

CVE ID :CVE-2026-5758 Published : April 15, 2026, 5:20 p.m. | 37 minutes ago Description :JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026

Pagina 2248 di 3213

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.