Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38629 risultati

VulnerabilitàAlta
CVE-2019-25689 (CVSS 8.4)

HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2018-25258 (CVSS 8.4)

RGui 3.5.0 contains a local buffer overflow vulnerability in the GUI preferences dialog that allows attackers to bypass DEP protections through structured exception handling exploitation. Attackers can craft malicious input in the Language for menus and messages field to trigger a stack-based buffer overflow, execute a ROP chain for VirtualAlloc allocation, and achieve arbitrary code execution.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2018-25257 (CVSS 7.1)

Adianti Framework 5.5.0 and 5.6.0 contains an SQL injection vulnerability that allows authenticated users to manipulate database queries by injecting SQL code through the name field in SystemProfileForm. Attackers can submit crafted SQL statements in the profile edit endpoint to modify user credentials and gain administrative access.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2019-25689 - HTML5 Video Player 1.2.5 Local Buffer Overflow Non-SEH

CVE ID :CVE-2019-25689 Published : April 12, 2026, 1:16 p.m. | 8 hours, 40 minutes ago Description :HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2018-25257 - Adianti Framework 5.5.0 and 5.6.0 SQL Injection via Profile

CVE ID :CVE-2018-25257 Published : April 12, 2026, 1:16 p.m. | 6 hours, 40 minutes ago Description :Adianti Framework 5.5.0 and 5.6.0 contains an SQL injection vulnerability that allows authenticated users to manipulate database queries by injecting SQL code through the name field in SystemProfileForm. Attackers can submit crafted SQL statements in the profile edit endpoint to modify user credentials and gain administrative access. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2018-25258 - RGui 3.5.0 Local Buffer Overflow SEH DEP Bypass

CVE ID :CVE-2018-25258 Published : April 12, 2026, 1:16 p.m. | 8 hours, 40 minutes ago Description :RGui 3.5.0 contains a local buffer overflow vulnerability in the GUI preferences dialog that allows attackers to bypass DEP protections through structured exception handling exploitation. Attackers can craft malicious input in the Language for menus and messages field to trigger a stack-based buffer overflow, execute a ROP chain for VirtualAlloc allocation, and achieve arbitrary code execution. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2017-20239 - MDwiki Cross-Site Scripting via Location Hash Parameter

CVE ID :CVE-2017-20239 Published : April 12, 2026, 1:16 p.m. | 4 hours, 40 minutes ago Description :MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by injecting malicious code through the location hash parameter. Attackers can craft URLs with JavaScript payloads in the hash fragment that are parsed and rendered without sanitization, causing the injected scripts to execute in the victim's browser context. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2026-6126 (CVSS 7.3)

A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2026-6126 - zhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authentication

CVE ID :CVE-2026-6126 Published : April 12, 2026, 11:16 a.m. | 6 hours, 41 minutes ago Description :A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2026-6125 - Dromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection

CVE ID :CVE-2026-6125 Published : April 12, 2026, 10:16 a.m. | 7 hours, 41 minutes ago Description :A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. The manipulation of the argument listenerPath/skipCondition/permissionFlag results in code injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2026-6124 (CVSS 8.8)

A vulnerability was determined in Tenda F451 1.0.0.7. This vulnerability affects the function fromSafeMacFilter of the file /goform/SafeMacFilter of the component httpd. Executing a manipulation of the argument page/menufacturer can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2026-6124 - Tenda F451 httpd SafeMacFilter fromSafeMacFilter stack-based overflow

CVE ID :CVE-2026-6124 Published : April 12, 2026, 9:16 a.m. | 8 hours, 41 minutes ago Description :A vulnerability was determined in Tenda F451 1.0.0.7. This vulnerability affects the function fromSafeMacFilter of the file /goform/SafeMacFilter of the component httpd. Executing a manipulation of the argument page/menufacturer can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026

Pagina 2314 di 3220

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.