News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38581 risultati
CVE ID :CVE-2025-69993 Published : April 14, 2026, 3:16 p.m. | 41 minutes ago Description :Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., ). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical—9 Vulnerabilities in Orthanc DICOM Servers Threaten Medical Data Integrity A series of critical security flaws has been uncovered in Orthanc, the popular open-source “lightweight Digital Imaging and Communications in Medicine (DICOM) server used to store, process, and retrie ... Read more Published Date: Apr 14, 2026 (18 hours, 34 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-5412 CVE-2026-5443 CVE-2026-5442 CVE-2026-5440 CVE-2026-5438 CVE-2026-22679 CVE-2026-35616 CVE-2026-27728 CVE-2025-2263
Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security Google has announced the integration of a Rust-based Domain Name System (DNS) parser into the modem firmware as part of its ongoing efforts to beef up the security of Pixel devices and push memory-saf ... Read more Published Date: Apr 14, 2026 (18 hours, 50 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2025-55182 CVE-2024-27227
CVE ID :CVE-2026-2450 Published : April 14, 2026, 1:16 p.m. | 41 minutes ago Description :.NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Hijacking a Privileged Thread of Execution.This issue affects upKeeper Instant Privilege Access: through 1.5.0. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-5307 Published : April 14, 2026, 1:16 p.m. | 41 minutes ago Description :Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2024-9168 Published : April 14, 2026, 1:16 p.m. | 41 minutes ago Description :Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-8095 Published : April 14, 2026, 1:13 p.m. | 44 minutes ago Description :The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-7389 Published : April 14, 2026, 1:12 p.m. | 44 minutes ago Description :A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself. The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile() methods exposed through the RMI interface. Misuse was limited only by OS-level authority of the AdminServer's elevated privileges granted and the user's access to these methods enabled through RMI. The exploitable methods have been removed thus eliminating their access through RMI or downstream of the RMI registry. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Juju’s CVSS 10 Flaw Hands Over Master Cloud Credentials Juju, the popular open-source application orchestration engine, is facing a critical security emergency. A newly discovered vulnerability, carrying the maximum possible severity rating of CVSS 10, all ... Read more Published Date: Apr 14, 2026 (19 hours, 39 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-4810 CVE-2026-5412 CVE-2026-22679 CVE-2026-35616 CVE-2026-4370
CVE-2026-4810: Critical 9.3 RCE Flaw Hits Google’s AI Agent Development Kit A recently disclosed vulnerability in Google’s Agent Development Kit (ADK) serves as a stark reminder that even the most modular frameworks are not immune to classic security pitfalls. Security resear ... Read more Published Date: Apr 14, 2026 (20 hours, 4 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-4810 CVE-2026-5412 CVE-2026-22679 CVE-2026-35616 CVE-2026-24164 CVE-2026-21962
SAP dicht kritiek SQL Injection-lek in Business Planning en Business Warehouse SAP heeft een kritieke kwetsbaarheid in Business Planning en Business Warehouse gedicht waardoor een ongeautoriseerde aanvaller op afstand willekeurige SQL-commando's op de database kan uitvoeren. De ... Read more Published Date: Apr 14, 2026 (18 hours, 18 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34256 CVE-2026-27681
CVE ID :CVE-2026-2449 Published : April 14, 2026, 12:16 p.m. | 1 hour, 41 minutes ago Description :Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Hijacking a Privileged Thread of Execution.This issue affects upKeeper Instant Privilege Access: through 1.5.0. Severity: 9.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2278 di 3216