News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38564 risultati
CVE ID :CVE-2026-4682 Published : April 15, 2026, 3:16 p.m. | 41 minutes ago Description :Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP. WSD Scan is a Microsoft Windows–based network scanning protocol that allows a PC to discover scanners (and MFPs) on a network and send scan jobs to them without requiring vendor specific drivers or utilities. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4667 Published : April 15, 2026, 3:16 p.m. | 41 minutes ago Description :HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-30364 Published : April 15, 2026, 3:16 p.m. | 41 minutes ago Description :CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2024-53412 Published : April 15, 2026, 3:16 p.m. | 41 minutes ago Description :Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-12141 Published : April 15, 2026, 2:59 p.m. | 58 minutes ago Description :In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations. Severity: 1.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Windows Active Directory Vulnerability Allow Attackers to Execute Malicious Code Microsoft has released urgent security updates to address a critical vulnerability in Windows Active Directory that allows attackers to execute malicious code. Disclosed on April 14, 2026, the vulnera ... Read more Published Date: Apr 15, 2026 (22 hours, 40 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33826
New PHP Composer Vulnerability Let Attackers Execute Arbitrary Commands PHP Composer released urgent security updates to address two critical command injection vulnerabilities. PHP Composer is an essential dependency management tool used globally by developers, making any ... Read more Published Date: Apr 15, 2026 (22 hours, 43 minutes ago) Vulnerabilities has been mentioned in this article.
Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code Adobe has released a critical security bulletin on April 14, 2026, to address multiple vulnerabilities in Adobe Acrobat and Reader for Windows and macOS. According to the official advisory, successful ... Read more Published Date: Apr 15, 2026 (22 hours, 46 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34626 CVE-2026-34622
IoT Under Fire: Critical CVSS 10 Expression Injection Hits OpenRemote Platform Security researchers have sounded a major alarm for the internet-of-things (IoT) sector as OpenRemote, a popular 100% open-source management platform, disclosed a maximum-severity vulnerability. The f ... Read more Published Date: Apr 15, 2026 (22 hours, 48 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-39842 CVE-2026-32201 CVE-2026-22679
Capsule Security debuts with $7 million funding to secure AI agent behavior Capsule Security has launched from stealth with a $7 million seed round led by Lama Partners and Forgepoint Capital International. It prevents AI agents from being manipulated, misbehaving, or silentl ... Read more Published Date: Apr 15, 2026 (22 hours, 52 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-21520
MuddyWater-Style Hackers Scan 12,000+ Systems Before Hitting Middle East Critical Sectors A sophisticated cyber campaign bearing strong operational similarities to the MuddyWater threat group has been caught sweeping more than 12,000 internet-exposed systems across multiple regions before ... Read more Published Date: Apr 15, 2026 (23 hours, 43 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-52691 CVE-2025-68613 CVE-2025-34291 CVE-2025-9316 CVE-2025-54068
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover A recently disclosed critical security flaw impacting nginx-ui, an open-source, web-based Nginx management tool, has come under active exploitation in the wild. The vulnerability in question is CVE-20 ... Read more Published Date: Apr 15, 2026 (21 hours, 55 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2026-33032 CVE-2026-27825 CVE-2026-27826 CVE-2025-55182
Pagina 2252 di 3214