Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38653 risultati

News
Multiple TP-Link Vulnerabilities Allow Attackers to Seize Control of the Device

Multiple TP-Link Vulnerabilities Allow Attackers to Seize Control of the Device Cybersecurity researchers have identified five distinct security flaws in the TP-Link Archer AX53 v1.0 router. Tracked under multiple CVE identifiers, these vulnerabilities impact the router’s core mo ... Read more Published Date: Apr 10, 2026 (3 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-30818 CVE-2026-30817 CVE-2026-30816 CVE-2026-30815 CVE-2026-30814

CVEfeed Newsroom10 apr 2026
VulnerabilitàAlta
CVE-2026-6035 - code-projects Vehicle Showroom Management System ServiceAndSalesReport.php cross site scripting

CVE ID :CVE-2026-6035 Published : April 10, 2026, 8:16 a.m. | 5 hours, 40 minutes ago Description :A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unknown function of the file /BranchManagement/ServiceAndSalesReport.php. The manipulation of the argument BRANCH_ID leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6031 (CVSS 7.3)

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the file /add-category-function.php. Such manipulation of the argument Category leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

NVD (NIST)10 apr 2026
VulnerabilitàAlta
CVE-2026-6033 - CodeAstro Online Classroom updatedetailsfromstudent.php sql injection

CVE ID :CVE-2026-6033 Published : April 10, 2026, 8:16 a.m. | 3 hours, 40 minutes ago Description :A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fname can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-5525 - Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoS

CVE ID :CVE-2026-5525 Published : April 10, 2026, 8:16 a.m. | 3 hours, 40 minutes ago Description :A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checking, resulting in a stack buffer overflow and application crash (STATUS_STACK_BUFFER_OVERRUN). Severity: 6.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6034 - code-projects Vehicle Showroom Management System ProfitAndLossReport.php cross site scripting

CVE ID :CVE-2026-6034 Published : April 10, 2026, 8:16 a.m. | 5 hours, 40 minutes ago Description :A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /BranchManagement/ProfitAndLossReport.php. Executing a manipulation of the argument BRANCH_ID can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-40212 - OpenStack Skyline DOM-Based Cross-Site Scripting (XSS)

CVE ID :CVE-2026-40212 Published : April 10, 2026, 8:16 a.m. | 3 hours, 40 minutes ago Description :OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-22750 - SSL bundle configuration silently bypassed in Spring Cloud Gateway

CVE ID :CVE-2026-22750 Published : April 10, 2026, 8:16 a.m. | 3 hours, 40 minutes ago Description :When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gateway 4.2.0 and are not an enterprise customer, you can upgrade to any Spring Cloud Gateway 4.2.x release newer than 4.2.0 available on Maven Centeral https://repo1.maven.org/maven2/org/springframework/cloud/spring-cloud-gateway/ . Ideally if you are not an enterprise customer, you should be upgrading to 5.0.2 or 5.1.1 which are the current supported open source releases. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
News
Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device

Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device A critical security alert warns of a severe default password vulnerability affecting Support Insights Virtual Lightweight Collector (vLWC) appliances. This flaw enables unauthenticated network-based a ... Read more Published Date: Apr 10, 2026 (3 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33784

CVEfeed Newsroom10 apr 2026
News
React Server Components Vulnerability Enables DoS Attacks

React Server Components Vulnerability Enables DoS Attacks A high-severity vulnerability has been discovered in React Server Components, exposing modern web applications to Denial of Service (DoS) attacks. Tracked as CVE-2026-23869, this flaw allows unauthent ... Read more Published Date: Apr 10, 2026 (3 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-23869

CVEfeed Newsroom10 apr 2026
News
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig. T ... Read more Published Date: Apr 10, 2026 (3 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-39987 CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2025-55182

CVEfeed Newsroom10 apr 2026
News
April 2026 Patch Tuesday forecast: Spring-cleaning of a preview

April 2026 Patch Tuesday forecast: Spring-cleaning of a preview I just blinked and the first quarter of the year is GONE. Where does the time go? I looked back at my article from last month where I touched on the use of AI and some of the vulnerabilities associate ... Read more Published Date: Apr 10, 2026 (3 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197 CVE-2026-5281

CVEfeed Newsroom10 apr 2026

Pagina 2333 di 3222

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.