News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38564 risultati
Microsoft Defender 0-Day Vulnerability Enables Privilege Escalation Attack Microsoft has released patch Tuesday security updates to address a newly discovered zero-day vulnerability in the Microsoft Defender Antimalware Platform. Disclosed on April 14, 2026, the flaw is trac ... Read more Published Date: Apr 15, 2026 (23 hours, 17 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33825
CVE ID :CVE-2026-5088 Published : April 15, 2026, 7:03 a.m. | 2 hours, 54 minutes ago Description :Apache::API::Password versions through v0.5.2 for Perl can generate insecure random values for salts. The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::Random::Secure to generate random bytes for the salt. If those modules are unavailable, it will simply return 16 bytes generated with Perl's built-in rand function. The rand function is unsuitable for cryptographic use. These salts are used for password hashing. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6293 Published : April 15, 2026, 6:46 a.m. | 3 hours, 11 minutes ago Description :The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combined with insufficient input sanitization on all user-supplied fields and missing output escaping when rendering stored values. The settings handler fires solely on the presence of `$_POST['inq_hidden'] == 'Y'` with no call to `check_admin_referer()` and no WordPress nonce anywhere in the form or handler. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via a forged request that tricks a logged-in Administrator into visiting a malicious page. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40719 Published : April 15, 2026, 6:23 a.m. | 3 hours, 34 minutes ago Description :Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Microsoft Fixes 167 Vulnerabilities in Latest Patch Tuesday Update Microsoft’s Patch Tuesday April 2026 release has introduced one of the most extensive security update rollouts of the year, addressing a total of 167 vulnerabilities across Windows operating systems a ... Read more Published Date: Apr 15, 2026 (20 hours, 38 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33827 CVE-2026-33826 CVE-2026-33825 CVE-2026-33824 CVE-2026-33115 CVE-2026-33114 CVE-2026-32201 CVE-2026-32190 CVE-2026-32157 CVE-2026-26169 CVE-2026-23666 CVE-2026-0390 CVE-2026-34621 CVE-2026-4681 CVE-2025-53783 CVE-2025-20337 CVE-2025-5777 CVE-2025-24200
CVE ID :CVE-2026-5160 Published : April 15, 2026, 5 a.m. | 2 hours, 57 minutes ago Description :Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities. This allows an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references. For example, a payload such as javascript:alert(1) is not recognized as dangerous during validation, leading to arbitrary script execution in the context of applications that render the URL. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-26291 Published : April 15, 2026, 4:19 a.m. | 3 hours, 38 minutes ago Description :Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arbitrary script may be executed in a user's web browser. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-5397 Published : April 15, 2026, 4:11 a.m. | 3 hours, 46 minutes ago Description :It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges. If a malicious DLL is placed in the installation directory of this product, there is a possibility that the malicious DLL may be executed by exploiting the product’s behavior of loading missing DLLs from the same directory as the executable during service startup. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-1555 Published : April 15, 2026, 3:37 a.m. | 4 hours, 20 minutes ago Description :The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Adobe Rushes Patches for Critical ColdFusion RCE and Security Bypasses Adobe has released an urgent set of security updates to address multiple vulnerabilities within its ColdFusion 2025 and 2023 versions. The patches resolve a range of critical and moderate security gap ... Read more Published Date: Apr 15, 2026 (23 hours, 32 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34619 CVE-2026-27307 CVE-2026-27306 CVE-2026-27304 CVE-2026-27282 CVE-2026-32201 CVE-2026-39813 CVE-2026-39808 CVE-2026-22679 CVE-2026-35616 CVE-2026-21570 CVE-2026-21962
CVE ID :CVE-2026-6328 Published : April 15, 2026, 3:18 a.m. | 4 hours, 39 minutes ago Description :Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through 1.8.3. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical 9.1 Flaws Hit Fortinet FortiSandbox Fortinet has issued an urgent advisory regarding two critical vulnerabilities in its FortiSandbox platform—vulnerabilities that could allow unauthenticated attackers to bypass security entirely and se ... Read more Published Date: Apr 15, 2026 (21 hours, 43 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-32201 CVE-2026-39813 CVE-2026-39808 CVE-2026-22679 CVE-2026-35616 CVE-2026-21643 CVE-2025-64155 CVE-2023-37936 CVE-2023-34992
Pagina 2258 di 3214