Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38603 risultati

VulnerabilitàAlta
CVE-2026-40394 - Varnish Cache HTTP/2 Denial of Service

CVE ID :CVE-2026-40394 Published : April 12, 2026, 8:16 p.m. | 7 hours, 41 minutes ago Description :Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repurposed as stream zero. During the upgrade, a buffer allocation is made to reserve space to send frames to the client. This allocation would split the original workspace, and depending on the amount of prefetched data, the next fetch could perform a pipelining operation that would run out of workspace. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2026-40385 - Nikon Libexif Integer Overflow Vulnerability

CVE ID :CVE-2026-40385 Published : April 12, 2026, 7:16 p.m. | 6 hours, 41 minutes ago Description :In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2026-40386 - Fujifilm/Olympus MakerNote Integer Underflow

CVE ID :CVE-2026-40386 Published : April 12, 2026, 7:16 p.m. | 6 hours, 41 minutes ago Description :In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2026-40393 - Mesa WebGPU Out-of-Bounds Memory Access Vulnerability

CVE ID :CVE-2026-40393 Published : April 12, 2026, 7:16 p.m. | 6 hours, 41 minutes ago Description :In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
News
CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly

CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly A critical security vulnerability in Axios, the ubiquitous promise-based HTTP client for Node.js and the browser, has been revealed to the public. Tracked as CVE-2026-40175 with a maximum CVSS score o ... Read more Published Date: Apr 12, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom12 apr 2026
VulnerabilitàAlta
CVE-2019-25713 (CVSS 7.1)

MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blind, or stacked query payloads to extract sensitive database information or manipulate data.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2019-25710 (CVSS 8.2)

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2019-25712 - BlueAuditor 1.7.2.0 Buffer Overflow Denial of Service via Registration Key

CVE ID :CVE-2019-25712 Published : April 12, 2026, 1:16 p.m. | 12 hours, 40 minutes ago Description :BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registration field, causing the application to crash during registration processing. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2019-25710 - Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter

CVE ID :CVE-2019-25710 Published : April 12, 2026, 1:16 p.m. | 12 hours, 40 minutes ago Description :Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2019-25711 - SpotFTP Password Recover 2.4.2 Denial of Service via Name Field

CVE ID :CVE-2019-25711 Published : April 12, 2026, 1:16 p.m. | 12 hours, 40 minutes ago Description :SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash when submitting the registration code. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2019-25713 - MyT-PM 1.5.1 SQL Injection via Charge[group_total] Parameter

CVE ID :CVE-2019-25713 Published : April 12, 2026, 1:16 p.m. | 12 hours, 40 minutes ago Description :MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blind, or stacked query payloads to extract sensitive database information or manipulate data. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàCritica
CVE-2019-25709 (CVSS 9.8)

CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.

NVD (NIST)12 apr 2026

Pagina 2309 di 3217

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.