Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38642 risultati

VulnerabilitàAlta
CVE-2026-40224 - "Systemd Machined Varlink Privilege Escalation"

CVE ID :CVE-2026-40224 Published : April 10, 2026, 3:14 p.m. | 42 minutes ago Description :In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
News
Bringing Rust to the Pixel Baseband

Bringing Rust to the Pixel Baseband Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex ... Read more Published Date: Apr 10, 2026 (2 days, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-27227

CVEfeed Newsroom10 apr 2026
VulnerabilitàAlta
CVE-2026-29002 - CouchCMS Privilege Escalation via f_k_levels_list Parameter

CVE ID :CVE-2026-29002 Published : April 10, 2026, 3:11 p.m. | 45 minutes ago Description :CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. Attackers can modify the parameter value from 4 to 10 in the HTTP request body to bypass authorization validation and gain full application control, circumventing restrictions on SuperAdmin account creation and privilege assignment. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-40223 - Systemd Assert Vulnerability

CVE ID :CVE-2026-40223 Published : April 10, 2026, 3:10 p.m. | 45 minutes ago Description :In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User= unit exists and is running. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-40217 - LiteLLM Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-40217 Published : April 10, 2026, 2:16 p.m. | 1 hour, 40 minutes ago Description :LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6069 - CVE-2026-6069

CVE ID :CVE-2026-6069 Published : April 10, 2026, 2:16 p.m. | 1 hour, 40 minutes ago Description :NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6068 - CVE-2026-6068

CVE ID :CVE-2026-6068 Published : April 10, 2026, 2:16 p.m. | 1 hour, 40 minutes ago Description :NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavior. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6067 - CVE-2026-6067

CVE ID :CVE-2026-6067 Published : April 10, 2026, 2:16 p.m. | 1 hour, 40 minutes ago Description :A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and arbitrary code execution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2025-58920 - WordPress Cerato theme <= 2.2.18 - Reflected Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2025-58920 Published : April 10, 2026, 2:16 p.m. | 1 hour, 40 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato allows Reflected XSS.This issue affects Cerato: from n/a through 2.2.18. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2025-58913 - WordPress VideoPro theme <= 2.3.8.1 - Local File Inclusion vulnerability

CVE ID :CVE-2025-58913 Published : April 10, 2026, 2:16 p.m. | 1 hour, 40 minutes ago Description :Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CactusThemes VideoPro allows PHP Local File Inclusion.This issue affects VideoPro: from n/a through 2.3.8.1. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2025-5804 - WordPress Case Theme User < 1.0.4 - Local File Inclusion Vulnerability

CVE ID :CVE-2025-5804 Published : April 10, 2026, 2:16 p.m. | 1 hour, 40 minutes ago Description :Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case Themes Case Theme User allows PHP Local File Inclusion.This issue affects Case Theme User: from n/a before 1.0.4. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-33092 - Acronis True Image OEM/MacOS Privilege Escalation

CVE ID :CVE-2026-33092 Published : April 10, 2026, 2:16 p.m. | 1 hour, 40 minutes ago Description :Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026

Pagina 2329 di 3221

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.