Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38642 risultati

VulnerabilitàAlta
CVE-2021-47961 - Synology SSL VPN Client Plaintext Password Storage Vulnerability

CVE ID :CVE-2021-47961 Published : April 10, 2026, 10:16 a.m. | 3 hours, 40 minutes ago Description :A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2021-47960 - Synology SSL VPN Client Information Disclosure

CVE ID :CVE-2021-47960 Published : April 10, 2026, 10:16 a.m. | 3 hours, 40 minutes ago Description :A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6057 - Unauthenticated Path Traversal in FalkorDB Browser Leads to Remote Code Execution

CVE ID :CVE-2026-6057 Published : April 10, 2026, 10:16 a.m. | 3 hours, 40 minutes ago Description :FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6038 (CVSS 7.3)

A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function of the file /util/RegisterCustomerFunction.php. Such manipulation of the argument BRANCH_ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

NVD (NIST)10 apr 2026
VulnerabilitàAlta
CVE-2026-6037 (CVSS 7.3)

A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function of the file /util/AddVehicleFunction.php. This manipulation of the argument BRANCH_ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

NVD (NIST)10 apr 2026
VulnerabilitàAlta
CVE-2026-6042 - musl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity

CVE ID :CVE-2026-6042 Published : April 10, 2026, 9:16 a.m. | 4 hours, 40 minutes ago Description :A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6038 - code-projects Vehicle Showroom Management System RegisterCustomerFunction.php sql injection

CVE ID :CVE-2026-6038 Published : April 10, 2026, 9:16 a.m. | 4 hours, 40 minutes ago Description :A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function of the file /util/RegisterCustomerFunction.php. Such manipulation of the argument BRANCH_ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6037 - code-projects Vehicle Showroom Management System AddVehicleFunction.php sql injection

CVE ID :CVE-2026-6037 Published : April 10, 2026, 9:16 a.m. | 4 hours, 40 minutes ago Description :A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function of the file /util/AddVehicleFunction.php. This manipulation of the argument BRANCH_ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6036 (CVSS 7.3)

A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown function of the file /util/VehicleDetailsFunction.php. The manipulation of the argument VEHICLE_ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

NVD (NIST)10 apr 2026
VulnerabilitàAlta
CVE-2026-33457 - Potential livestatus injection in prediction graph page

CVE ID :CVE-2026-33457 Published : April 10, 2026, 9:16 a.m. | 4 hours, 40 minutes ago Description :Livestatus injection in the prediction graph page in Checkmk Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-33456 - Potential livestatus injection in notification test

CVE ID :CVE-2026-33456 Published : April 10, 2026, 9:16 a.m. | 4 hours, 40 minutes ago Description :Livestatus injection in the notification test mode in Checkmk Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6036 - code-projects Vehicle Showroom Management System VehicleDetailsFunction.php sql injection

CVE ID :CVE-2026-6036 Published : April 10, 2026, 9:16 a.m. | 4 hours, 40 minutes ago Description :A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown function of the file /util/VehicleDetailsFunction.php. The manipulation of the argument VEHICLE_ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026

Pagina 2331 di 3221

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.