Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38586 risultati

VulnerabilitàAlta
CVE-2026-22566 - Ubiquiti UniFi Play WiFi Credentials Exposure

CVE ID :CVE-2026-22566 Published : April 13, 2026, 10:16 p.m. | 1 hour, 41 minutes ago Description :An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version 1.0.38 or later Update UniFi Play Audio Port to Version 1.1.9 or later Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-22565 - "UniFi Play PowerAmp and Audio Port Improper Input Validation Denial of Service"

CVE ID :CVE-2026-22565 Published : April 13, 2026, 10:16 p.m. | 1 hour, 41 minutes ago Description :An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop responding. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version 1.0.38 or later Update UniFi Play Audio Port to Version 1.1.9 or later Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-22564 - "UniFi Play Improper Access Control SSH Enablement Vulnerability"

CVE ID :CVE-2026-22564 Published : April 13, 2026, 10:16 p.m. | 1 hour, 41 minutes ago Description :An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version 1.0.38 or later Update UniFi Play Audio Port to Version 1.1.9 or later Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-40169 - ImageMagick: Heap buffer overflow (WRITE) in the YAML and JSON encoders

CVE ID :CVE-2026-40169 Published : April 13, 2026, 10:16 p.m. | 1 hour, 41 minutes ago Description :ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-6216 - DbGate SVG Icon String FontIcon.svelte cross site scripting

CVE ID :CVE-2026-6216 Published : April 13, 2026, 9:16 p.m. | 2 hours, 41 minutes ago Description :A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 7.1.5 mitigates this issue. It is advisable to upgrade the affected component. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-6219 - aandrew-me ytDownloader Compressor Feature compressor.js child_process.exec command injection

CVE ID :CVE-2026-6219 Published : April 13, 2026, 9:16 p.m. | 2 hours, 41 minutes ago Description :A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of the component Compressor Feature. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-6218 - aandrew-me ytDownloader Error Details Panel createTextNode cross site scripting

CVE ID :CVE-2026-6218 Published : April 13, 2026, 9:16 p.m. | 2 hours, 41 minutes ago Description :A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosure. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-33900 - ImageMagick has a Heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds

CVE ID :CVE-2026-33900 Published : April 13, 2026, 9:16 p.m. | 41 minutes ago Description :ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-189 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-33899 - ImageMagick: Heap BufferOverflow write of single zero byte when parsing XML

CVE ID :CVE-2026-33899 Published : April 13, 2026, 9:16 p.m. | 41 minutes ago Description :ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-33901 - ImageMagick has a Heap Buffer Overflow via MVG decoder

CVE ID :CVE-2026-33901 Published : April 13, 2026, 9:16 p.m. | 41 minutes ago Description :ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-33740 - EspoCRM: Email importEml can import and delete another user's attachment by raw fileId

CVE ID :CVE-2026-33740 Published : April 13, 2026, 9:16 p.m. | 41 minutes ago Description :EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vulnerability where the attacker-supplied fileId parameter is used to fetch any attachment directly from the repository without verifying that the current user has authorization to access it. Any authenticated user with Email:create and Import permissions can exploit this to read another user's .eml attachment contents by importing them as a new email into the attacker's mailbox, while the original victim attachment record is deleted as a side effect of the import flow. This is inconsistent with the standard attachment download path, which enforces ACL checks before returning file data, and is practically exploitable because attachment IDs are commonly exposed in normal UI and API workflows such as stream payloads and download links. This issue is fixed in version 9.3.4. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-31280 - Parani M10 Motorcycle Intercom RFCOMM Service DoS Vulnerability

CVE ID :CVE-2026-31280 Published : April 13, 2026, 9:16 p.m. | 41 minutes ago Description :An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause a Denial of Service (DoS) via supplying crafted RFCOMM frames. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026

Pagina 2288 di 3216

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.