Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38581 risultati

News
CISA Warns of Fortinet SQL Injection Vulnerability Actively Exploited in Attacks

CISA Warns of Fortinet SQL Injection Vulnerability Actively Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in Fortinet products. On April 13, 2026, the agency added a severe SQL injec ... Read more Published Date: Apr 14, 2026 (18 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-21643

CVEfeed Newsroom14 apr 2026
News
CVE-2026-4631: Critical 9.8 RCE Flaw in Cockpit Allows Unauthenticated Server Takeover

CVE-2026-4631: Critical 9.8 RCE Flaw in Cockpit Allows Unauthenticated Server Takeover In the world of Linux server management, ease of use and security are intended to go hand-in-hand. However, a critical vulnerability discovered in Cockpit, the lightweight and popular interactive serv ... Read more Published Date: Apr 14, 2026 (18 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-4631 CVE-2026-22679 CVE-2026-35616

CVEfeed Newsroom14 apr 2026
VulnerabilitàAlta
CVE-2026-24069 - Improper Enforcement of Disabled Accounts in WebUI SSO in Kiuwan SAST

CVE ID :CVE-2026-24069 Published : April 14, 2026, 12:16 p.m. | 1 hour, 41 minutes ago Description :Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 apr 2026
VulnerabilitàAlta
CVE-2025-13822 - Authentication bypass in MCPHub

CVE ID :CVE-2025-13822 Published : April 14, 2026, 11:16 a.m. | 2 hours, 41 minutes ago Description :MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 apr 2026
VulnerabilitàAlta
CVE-2026-2332 - HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

CVE ID :CVE-2026-2332 Published : April 14, 2026, 12:16 p.m. | 1 hour, 41 minutes ago Description :In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 apr 2026
News
Vulnerability in MCPHub software

Vulnerability in MCPHub software Vulnerability in MCPHub software CVE ID CVE-2025-13822 Publication date 14 April 2026 Vendor MCPHub Product MCPHub Vulnerable versions All before 0.11.0 Vulnerability type (CWE) Authorization Bypass T ... Read more Published Date: Apr 14, 2026 (15 hours, 48 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-13822

CVEfeed Newsroom14 apr 2026
News
Supply Chain Sabotage: The Critical RCE Flaws Lurking in PHP Composer

Supply Chain Sabotage: The Critical RCE Flaws Lurking in PHP Composer In the PHP ecosystem, Composer is the undisputed heavy hitter for dependency management, responsible for orchestrating the libraries that power millions of applications. However, security researchers ... Read more Published Date: Apr 14, 2026 (16 hours, 4 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom14 apr 2026
News
Micropatches released for Windows Shell Security Feature Bypass Vulnerability (CVE-2026-21510)

Micropatches released for Windows Shell Security Feature Bypass Vulnerability (CVE-2026-21510) February 2026 Windows Updates brought a patch for CVE-2026-21510, a security feature bypass in Windows Explorer that allowed a Windows shortcut to launch a remotely hosted DLL without any warning to t ... Read more Published Date: Apr 14, 2026 (16 hours, 42 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-21510

CVEfeed Newsroom14 apr 2026
VulnerabilitàAlta
CVE-2026-33892 (CVSS 7.1)

A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 < V2.8.0). Affected management systems do not properly enforce user authentication on remote connections to devices. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has identified the header and port used for remote connections to devices and that the remote connection feature is enabled for the device. Exploitation allows the attacker to tunnel to the device. Security features on this device itself (e.g. app specific authentication) are not affected.

NVD (NIST)14 apr 2026
VulnerabilitàAlta
CVE-2026-33892 - Industrial Edge Management Pro/Virtual Unauthenticated Remote Authentication Bypass

CVE ID :CVE-2026-33892 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 = V2.0.0 = V2.2.0 Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 apr 2026
VulnerabilitàAlta
CVE-2026-4109 - Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure

CVE ID :CVE-2026-4109 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order data including customer PII (name, email, phone) by iterating order IDs. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 apr 2026
VulnerabilitàAlta
CVE-2026-33929 - Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code

CVE ID :CVE-2026-33929 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are recommended to update to version 2.0.37 or 3.0.8 once available. Until then, they should apply the fix provided in GitHub PR 427. The ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. "/home/ABCDEF". Users who have copied this example into their production code should apply the mentioned change. The example has been changed accordingly and is available in the project repository. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 apr 2026

Pagina 2279 di 3216

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.