News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38581 risultati
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device group at any access level.
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the ability to reset the password of any arbitrary user account.
CVE ID :CVE-2026-25654 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :A vulnerability has been identified in SINEC NMS (All versions Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-31923 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-31924 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-31908 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-27668 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in the UMC component. This could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the application. (ZDI-CAN-27564)
CVE ID :CVE-2026-24032 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :A vulnerability has been identified in SINEC NMS (All versions Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-40745 Published : April 14, 2026, 9:16 a.m. | 4 hours, 41 minutes ago Description :A vulnerability has been identified in Siemens Software Center (All versions Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical wolfSSL Flaw Could Allow Attackers to Spoof Trusted Hosts In the world of embedded systems and resource-constrained environments, wolfSSL (formerly CyaSSL) is the lightweight champion of security. Known for its small footprint—up to 20 times smaller than Ope ... Read more Published Date: Apr 14, 2026 (17 hours, 31 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-5194 CVE-2026-22679 CVE-2026-35616 CVE-2025-13151 CVE-2025-14942
CISA Adds 7 Fresh Exploits to KEV Catalog The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog, adding seven high-risk flaws that are currently being weaponized by maliciou ... Read more Published Date: Apr 14, 2026 (17 hours, 56 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34621 CVE-2026-5194 CVE-2026-22679 CVE-2026-35616 CVE-2026-21643 CVE-2026-21962 CVE-2025-60710 CVE-2024-49035 CVE-2023-33063 CVE-2023-36424 CVE-2023-34192 CVE-2023-21529 CVE-2020-9715 CVE-2012-1854
Pagina 2280 di 3216