News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38704 risultati
CVE ID :CVE-2025-62718 Published : April 9, 2026, 3:16 p.m. | 40 minutes ago Description :Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-50228 Published : April 9, 2026, 3:16 p.m. | 40 minutes ago Description :Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-5960 Published : April 9, 2026, 4:16 p.m. | 1 hour, 39 minutes ago Description :A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /db/hcpms.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-35205 Published : April 9, 2026, 3:06 p.m. | 49 minutes ago Description :Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-14551 Published : April 9, 2026, 3:03 p.m. | 52 minutes ago Description :In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-35204 Published : April 9, 2026, 3:03 p.m. | 53 minutes ago Description :Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not include a version: field containing POSIX dot-dot path separators ie. "/../". This vulnerability is fixed in 4.1.4. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-15480 Published : April 9, 2026, 3:02 p.m. | 54 minutes ago Description :In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Cloud Engineering at Risk: AWS Patches Critical Privilege Escalation and RCE Flaws in RES Research and Engineering Studio on AWS architecture | Image: AWS Amazon Web Services (AWS) has released urgent security updates for its Research and Engineering Studio (RES), an open-source portal des ... Read more Published Date: Apr 09, 2026 (3 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22679 CVE-2026-5709 CVE-2026-5708 CVE-2026-5707 CVE-2026-35616 CVE-2026-5281 CVE-2026-3502 CVE-2026-1340
Critical 9.8 CVSS Flaws in goshs Exposed Security researchers have unmasked three critical vulnerabilities in goshs, a popular high-performance replacement for Python’s SimpleHTTPServer. The flaws, all involving improper limitation of pathna ... Read more Published Date: Apr 09, 2026 (3 days, 12 hours ago) Vulnerabilities has been mentioned in this article.
The “Open Door” Vulnerability: Unchanged Default Passwords Put Juniper vLWC at Risk In a critical security alert, Juniper Networks has warned of a severe vulnerability in its Support Insights (JSI) Virtual Lightweight Collector (vLWC). The flaw, tracked as CVE-2026-33784, carries a C ... Read more Published Date: Apr 09, 2026 (3 days, 12 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-3005 Published : April 9, 2026, 1:16 p.m. | 39 minutes ago Description :The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to, and including, 0.94.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-2519 Published : April 9, 2026, 1:16 p.m. | 39 minutes ago Description :The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2357 di 3226