News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38581 risultati
CISA Warns of Fortinet SQL Injection Vulnerability Actively Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in Fortinet products. On April 13, 2026, the agency added a severe SQL injec ... Read more Published Date: Apr 14, 2026 (18 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-21643
CVE-2026-4631: Critical 9.8 RCE Flaw in Cockpit Allows Unauthenticated Server Takeover In the world of Linux server management, ease of use and security are intended to go hand-in-hand. However, a critical vulnerability discovered in Cockpit, the lightweight and popular interactive serv ... Read more Published Date: Apr 14, 2026 (18 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-4631 CVE-2026-22679 CVE-2026-35616
CVE ID :CVE-2026-24069 Published : April 14, 2026, 12:16 p.m. | 1 hour, 41 minutes ago Description :Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-13822 Published : April 14, 2026, 11:16 a.m. | 2 hours, 41 minutes ago Description :MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-2332 Published : April 14, 2026, 12:16 p.m. | 1 hour, 41 minutes ago Description :In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerability in MCPHub software Vulnerability in MCPHub software CVE ID CVE-2025-13822 Publication date 14 April 2026 Vendor MCPHub Product MCPHub Vulnerable versions All before 0.11.0 Vulnerability type (CWE) Authorization Bypass T ... Read more Published Date: Apr 14, 2026 (15 hours, 48 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-13822
Supply Chain Sabotage: The Critical RCE Flaws Lurking in PHP Composer In the PHP ecosystem, Composer is the undisputed heavy hitter for dependency management, responsible for orchestrating the libraries that power millions of applications. However, security researchers ... Read more Published Date: Apr 14, 2026 (16 hours, 4 minutes ago) Vulnerabilities has been mentioned in this article.
Micropatches released for Windows Shell Security Feature Bypass Vulnerability (CVE-2026-21510) February 2026 Windows Updates brought a patch for CVE-2026-21510, a security feature bypass in Windows Explorer that allowed a Windows shortcut to launch a remotely hosted DLL without any warning to t ... Read more Published Date: Apr 14, 2026 (16 hours, 42 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-21510
A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 < V2.8.0). Affected management systems do not properly enforce user authentication on remote connections to devices. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has identified the header and port used for remote connections to devices and that the remote connection feature is enabled for the device. Exploitation allows the attacker to tunnel to the device. Security features on this device itself (e.g. app specific authentication) are not affected.
CVE ID :CVE-2026-33892 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 = V2.0.0 = V2.2.0 Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4109 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order data including customer PII (name, email, phone) by iterating order IDs. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-33929 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are recommended to update to version 2.0.37 or 3.0.8 once available. Until then, they should apply the fix provided in GitHub PR 427. The ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. "/home/ABCDEF". Users who have copied this example into their production code should apply the mentioned change. The example has been changed accordingly and is available in the project repository. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2279 di 3216