Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38738 risultati

VulnerabilitàAlta
CVE-2026-5960 - code-projects Patient Record Management System SQL Database Backup File hcpms.sql information disclosure

CVE ID :CVE-2026-5960 Published : April 9, 2026, 4:16 p.m. | 1 hour, 39 minutes ago Description :A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /db/hcpms.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2026-35205 - Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install

CVE ID :CVE-2026-35205 Published : April 9, 2026, 3:06 p.m. | 49 minutes ago Description :Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2025-14551 - Senstive information disclosure was affecting subiquity

CVE ID :CVE-2025-14551 Published : April 9, 2026, 3:03 p.m. | 52 minutes ago Description :In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2026-35204 - Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory

CVE ID :CVE-2026-35204 Published : April 9, 2026, 3:03 p.m. | 53 minutes ago Description :Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not include a version: field containing POSIX dot-dot path separators ie. "/../". This vulnerability is fixed in 4.1.4. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2025-15480 - Senstive information disclosure was affecting ubuntu-desktop-provision

CVE ID :CVE-2025-15480 Published : April 9, 2026, 3:02 p.m. | 54 minutes ago Description :In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
News
Cloud Engineering at Risk: AWS Patches Critical Privilege Escalation and RCE Flaws in RES

Cloud Engineering at Risk: AWS Patches Critical Privilege Escalation and RCE Flaws in RES Research and Engineering Studio on AWS architecture | Image: AWS Amazon Web Services (AWS) has released urgent security updates for its Research and Engineering Studio (RES), an open-source portal des ... Read more Published Date: Apr 09, 2026 (3 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22679 CVE-2026-5709 CVE-2026-5708 CVE-2026-5707 CVE-2026-35616 CVE-2026-5281 CVE-2026-3502 CVE-2026-1340

CVEfeed Newsroom09 apr 2026
News
Critical 9.8 CVSS Flaws in goshs Exposed

Critical 9.8 CVSS Flaws in goshs Exposed Security researchers have unmasked three critical vulnerabilities in goshs, a popular high-performance replacement for Python’s SimpleHTTPServer. The flaws, all involving improper limitation of pathna ... Read more Published Date: Apr 09, 2026 (3 days, 12 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 apr 2026
News
The “Open Door” Vulnerability: Unchanged Default Passwords Put Juniper vLWC at Risk

The “Open Door” Vulnerability: Unchanged Default Passwords Put Juniper vLWC at Risk In a critical security alert, Juniper Networks has warned of a severe vulnerability in its Support Insights (JSI) Virtual Lightweight Collector (vLWC). The flaw, tracked as CVE-2026-33784, carries a C ... Read more Published Date: Apr 09, 2026 (3 days, 12 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 apr 2026
VulnerabilitàAlta
CVE-2026-3005 - List category posts <= 0.94.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'catlist' Shortcode

CVE ID :CVE-2026-3005 Published : April 9, 2026, 1:16 p.m. | 39 minutes ago Description :The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to, and including, 0.94.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2026-2519 - Online Scheduling and Appointment Booking System – Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips'

CVE ID :CVE-2026-2519 Published : April 9, 2026, 1:16 p.m. | 39 minutes ago Description :The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
News
100,000+ Sites Exposed: Critical 9.8 CVSS Flaw Hits Everest Forms WordPress Plugin

100,000+ Sites Exposed: Critical 9.8 CVSS Flaw Hits Everest Forms WordPress Plugin Everest Forms, a popular WordPress plugin trusted by over 100,000 websites for building everything from simple contact forms to complex applications, has addressed a critical security vulnerability. T ... Read more Published Date: Apr 09, 2026 (3 days, 11 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 apr 2026
News
Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197)

Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197) In the latest demonstration of how AI assistants can help with bug hunting, Horizon3.ai researcher Naveen Sunkavally used Claude to unearth CVE-2026-34197, a remote code execution vulnerability in Apa ... Read more Published Date: Apr 09, 2026 (3 days, 11 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197 CVE-2024-32114 CVE-2023-46604

CVEfeed Newsroom09 apr 2026

Pagina 2360 di 3229

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.