Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38556 risultati

VulnerabilitàAlta
CVE-2026-20205 - Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app

CVE ID :CVE-2026-20205 Published : April 15, 2026, 3:17 p.m. | 40 minutes ago Description :In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text.The vulnerability would require either local access to the log files or administrative access to internal indexes, which by default only the admin role receives. Review roles and capabilities on your instance and restrict internal index access to administrator-level roles. See [Define roles on the Splunk platform with capabilities](https://docs.splunk.com/Documentation/Splunk/latest/Security/Rolesandcapabilities) and [Connecting to MCP Server and Admin settings](https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/connecting-to-mcp-server-and-admin-settings) in the Splunk documentation for more information. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-20203 - Improper Access Control in Data Model Acceleration in Splunk Enterprise

CVE ID :CVE-2026-20203 Published : April 15, 2026, 3:17 p.m. | 40 minutes ago Description :In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles, has write permission on the app, and does not hold the high-privilege capability `accelerate_datamodel`, could turn on or off Data Model Acceleration due to improper access control. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-20204 - Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterprise

CVE ID :CVE-2026-20204 Published : April 15, 2026, 3:17 p.m. | 40 minutes ago Description :In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform a Remote Code Execution (RCE) by uploading a malicious file to the `$SPLUNK_HOME/var/run/splunk/apptemp` directory due to improper handling and insufficient isolation of temporary files within the `apptemp` directory. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-20202 - Improper Input Validation during User Account Creation in Splunk Enterprise

CVE ID :CVE-2026-20202 Published : April 15, 2026, 3:17 p.m. | 40 minutes ago Description :In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a specially crafted username that includes a null byte or a non-UTF-8 percent-encoded byte due to improper input validation.This could lead to inconsistent conversion of usernames into a proper format for storage and account management inconsistencies, such as being unable to edit or delete affected users. Severity: 6.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-4667 - HP System Optimizer - Escalation of Privilege

CVE ID :CVE-2026-4667 Published : April 15, 2026, 3:16 p.m. | 41 minutes ago Description :HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-4682 - Certain HP DeskJet All In One (AIO) Devices – Potential Remote Code Execution & Potential Buffer Overflow

CVE ID :CVE-2026-4682 Published : April 15, 2026, 3:16 p.m. | 41 minutes ago Description :Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP. WSD Scan is a Microsoft Windows–based network scanning protocol that allows a PC to discover scanners (and MFPs) on a network and send scan jobs to them without requiring vendor specific drivers or utilities. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2026-30364 - CentSDR Stack Overflow Vulnerability

CVE ID :CVE-2026-30364 Published : April 15, 2026, 3:16 p.m. | 41 minutes ago Description :CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2024-53412 - NietThijmen ShoppingCart Command Injection Vulnerability

CVE ID :CVE-2024-53412 Published : April 15, 2026, 3:16 p.m. | 41 minutes ago Description :Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
VulnerabilitàAlta
CVE-2025-12141 - Grafana Alerting Editors can edit destination of webhooks they did not create

CVE ID :CVE-2025-12141 Published : April 15, 2026, 2:59 p.m. | 58 minutes ago Description :In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations. Severity: 1.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 apr 2026
News
Windows Active Directory Vulnerability Allow Attackers to Execute Malicious Code

Windows Active Directory Vulnerability Allow Attackers to Execute Malicious Code Microsoft has released urgent security updates to address a critical vulnerability in Windows Active Directory that allows attackers to execute malicious code. Disclosed on April 14, 2026, the vulnera ... Read more Published Date: Apr 15, 2026 (22 hours, 40 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33826

CVEfeed Newsroom15 apr 2026
News
New PHP Composer Vulnerability Let Attackers Execute Arbitrary Commands

New PHP Composer Vulnerability Let Attackers Execute Arbitrary Commands PHP Composer released urgent security updates to address two critical command injection vulnerabilities. PHP Composer is an essential dependency management tool used globally by developers, making any ... Read more Published Date: Apr 15, 2026 (22 hours, 43 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom15 apr 2026
News
Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code

Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code Adobe has released a critical security bulletin on April 14, 2026, to address multiple vulnerabilities in Adobe Acrobat and Reader for Windows and macOS. According to the official advisory, successful ... Read more Published Date: Apr 15, 2026 (22 hours, 46 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34626 CVE-2026-34622

CVEfeed Newsroom15 apr 2026

Pagina 2251 di 3213

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.