Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38603 risultati

VulnerabilitàAlta
CVE-2026-25208 - Samsung Open Source Escargot Integer Overflow Buffer Overflow

CVE ID :CVE-2026-25208 Published : April 13, 2026, 5:16 a.m. | 41 minutes ago Description :Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-21003 - Fortinet FortiOS Input Validation Bypass

CVE ID :CVE-2026-21003 Published : April 13, 2026, 5:16 a.m. | 41 minutes ago Description :Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions. Severity: 5.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-6157 (CVSS 8.8)

A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument apcliSsid results in buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

NVD (NIST)13 apr 2026
VulnerabilitàCritica
CVE-2026-6156 (CVSS 9.8)

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument Comment leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

NVD (NIST)13 apr 2026
VulnerabilitàCritica
CVE-2026-6155 (CVSS 9.8)

A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument pppoeServiceName can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

NVD (NIST)13 apr 2026
VulnerabilitàCritica
CVE-2026-6154 (CVSS 9.8)

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wizard results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)13 apr 2026
VulnerabilitàAlta
CVE-2026-6153 (CVSS 7.3)

A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /util/StaffDetailsFunction.php. Such manipulation of the argument STAFF_ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

NVD (NIST)13 apr 2026
News
Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint

Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint A critical flaw in marimo, a popular reactive Python notebook platform, has become the latest case study in how modern threat actors are weaponizing advisories with unprecedented speed. The vulnerabil ... Read more Published Date: Apr 13, 2026 (23 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-39987 CVE-2026-22679 CVE-2026-35616 CVE-2026-5281 CVE-2026-0866 CVE-2025-61622

CVEfeed Newsroom13 apr 2026
VulnerabilitàAlta
CVE-2026-6152 (CVSS 7.3)

A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/StaffAddingFunction.php. This manipulation of the argument STAFF_ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

NVD (NIST)13 apr 2026
VulnerabilitàAlta
CVE-2026-6179 - Stored Cross Site Scripting in NightWolf Penetration Testing Platform

CVE ID :CVE-2026-6179 Published : April 13, 2026, 3:16 a.m. | 41 minutes ago Description :Stored Cross Site Scripting in NightWolf Penetration Testing Platform allows attack trigger and run malicious script in user's browser Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-6151 (CVSS 7.3)

A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/PaymentStatusFunction.php. The manipulation of the argument CUSTOMER_ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

NVD (NIST)13 apr 2026
VulnerabilitàAlta
CVE-2026-6150 - code-projects Simple Laundry System checkupdatestatus.php cross site scripting

CVE ID :CVE-2026-6150 Published : April 13, 2026, 3:16 a.m. | 41 minutes ago Description :A vulnerability has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /checkupdatestatus.php. The manipulation of the argument serviceId leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026

Pagina 2305 di 3217

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.