Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38596 risultati

VulnerabilitàAlta
CVE-2026-31283 - Totara LMS Email Bombing Vulnerability

CVE ID :CVE-2026-31283 Published : April 13, 2026, 3:17 p.m. | 39 minutes ago Description :In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-30999 - FFmpeg Heap Buffer Overflow Denial of Service

CVE ID :CVE-2026-30999 Published : April 13, 2026, 3:17 p.m. | 39 minutes ago Description :A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-30997 - FFmpeg AV1 Decoding Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-30997 Published : April 13, 2026, 3:17 p.m. | 40 minutes ago Description :An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-30998 - FFmpeg ZMQSend Denial of Service

CVE ID :CVE-2026-30998 Published : April 13, 2026, 3:17 p.m. | 40 minutes ago Description :An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-31281 - Totara LMS HTML Injection

CVE ID :CVE-2026-31281 Published : April 13, 2026, 3:17 p.m. | 39 minutes ago Description :Totara LMS v19.1.5 and before is vulnerable to HTLM Injection. An attacker can inject malicious HTLM code in a message and send it to all the users in the application, resulting in executing the code and may lead to session hijacking and executing commands on the victim's browser. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-29628 - Tinyobjloader Stack Overflow Denial of Service

CVE ID :CVE-2026-29628 Published : April 13, 2026, 3:17 p.m. | 40 minutes ago Description :A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of Service (DoS) via supplying a crafted .mtl file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-1462 - Safe Mode Bypass in keras-team/keras

CVE ID :CVE-2026-1462 Published : April 13, 2026, 3:17 p.m. | 40 minutes ago Description :A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2025-66236 - Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

CVE ID :CVE-2025-66236 Published : April 13, 2026, 3:17 p.m. | 40 minutes ago Description :Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not clear or explicit enough, even though Airflow's intentions and security model of Airflow did not suggest different assumptions. The overall security model [1], workload isolation [2], and JWT authentication details [3] are now described in more detail. Users concerned with role isolation and following the Airflow security model of Airflow are advised to upgrade to Airflow 3.2, where several security improvements have been implemented. They should also read and follow the relevant documents to make sure that their deployment is secure enough. It also clarifies that the Deployment Manager is ultimately responsible for securing your Airflow deployment. This had also been communicated via Airflow 3.2.0 Blog announcement [4]. [1] Security Model: https://airflow.apache.org/docs/apache-airflow/stable/security/jwt_token_authentication.html [2] Workload isolation: https://airflow.apache.org/docs/apache-airflow/stable/security/workload.html [3] JWT Token authentication: https://airflow.apache.org/docs/apache-airflow/stable/security/jwt_token_authentication.html [4] Airflow 3.2.0 Blog announcement: https://airflow.apache.org/blog/airflow-3.2.0/ Users are recommended to upgrade to version 3.2.0, which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-6186 - UTT HiPER 1200GW formNatStaticMap strcpy buffer overflow

CVE ID :CVE-2026-6186 Published : April 13, 2026, 3:15 p.m. | 42 minutes ago Description :A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the function strcpy of the file /goform/formNatStaticMap. The manipulation of the argument NatBind leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-6184 - code-projects Simple Content Management System welcome.php cross site scripting

CVE ID :CVE-2026-6184 Published : April 13, 2026, 4:16 p.m. | 1 hour, 40 minutes ago Description :A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Title can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
News
Marimo RCE Vulnerability Exploited in the Within 10 Hours of Disclosure

Marimo RCE Vulnerability Exploited in the Within 10 Hours of Disclosure A critical vulnerability was disclosed in Marimo, an open-source reactive Python notebook platform. Less than 10 hours later, attackers successfully weaponized the flaw to steal sensitive cloud creden ... Read more Published Date: Apr 13, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-39987

CVEfeed Newsroom13 apr 2026
News
Critical Axios Vulnerability Allows Remote Code Execution – PoC Released

Critical Axios Vulnerability Allows Remote Code Execution – PoC Released The cybersecurity community is on high alert after the disclosure of a critical security flaw in Axios, a widely used promise-based HTTP client for Node.js and browsers. Security researcher Jason Saay ... Read more Published Date: Apr 13, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-40175

CVEfeed Newsroom13 apr 2026

Pagina 2295 di 3217

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.