News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38738 risultati
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories Thursday. Another week, another batch of things that probably should've been caught sooner but weren't.This one's got some range — old vulnerabilities getting new life, a few "why was that even possib ... Read more Published Date: Apr 09, 2026 (3 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197 CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2026-23226 CVE-2025-55182 CVE-2025-40039 CVE-2024-32114 CVE-2022-41678
Frontend Secrets Exposed: Vite Patches Critical Security Bypass in Dev Server Vite has become the “speed demon” of modern frontend development, prized for its lightning-fast Hot Module Replacement (HMR) and native ES module serving. However, two recently disclosed vulnerabiliti ... Read more Published Date: Apr 09, 2026 (2 days, 18 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-24661 Published : April 9, 2026, 11:16 a.m. | 2 hours, 40 minutes ago Description :Mattermost Plugins versions Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-57735 Published : April 9, 2026, 11:16 a.m. | 2 hours, 40 minutes ago Description :When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+ Users are recommended to upgrade to version 3.2.0, which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21388 Published : April 9, 2026, 11:16 a.m. | 2 hours, 40 minutes ago Description :Mattermost Plugins versions Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.
CVE ID :CVE-2024-1490 Published : April 9, 2026, 11:16 a.m. | 2 hours, 40 minutes ago Description :An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities in Hydrosystem Control System software Vulnerabilities in Hydrosystem Control System software CVE ID CVE-2026-4901 Publication date 09 April 2026 Vendor Hydrosystem Product Control System Vulnerable versions All before 9.8.5 Vulnerability ... Read more Published Date: Apr 09, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4901 CVE-2026-34185 CVE-2026-34184
CISA Warns of Critical Ivanti EPMM Code Injection Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in Ivanti Endpoint Manager Mobile (EPMM). The agency recently added this fla ... Read more Published Date: Apr 09, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-1340
GitLab Patches Multiple Vulnerabilities That Enables DoS and Code Injection Attacks GitLab has released urgent security updates (versions 18.10.3, 18.9.5, and 18.8.9) for its Community Edition (CE) and Enterprise Edition (EE) to address high-severity flaws that enable Denial-of-Servi ... Read more Published Date: Apr 09, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.
Multiple SonicWall Vulnerabilities Enable SQL Injection and Privilege Escalation Attacks SonicWall has released a critical security advisory addressing four vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances. These security flaws could allow remote attackers t ... Read more Published Date: Apr 09, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.
Palo Alto Cortex Microsoft Teams Integration Vulnerability Enables Data Access for Attackers Palo Alto Networks released an urgent update to patch a high-severity flaw (CVE-2026-0234) affecting the Microsoft Teams integration in Cortex XSOAR and Cortex XSIAM. This flaw could allow unauthorize ... Read more Published Date: Apr 09, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.
Pagina 2361 di 3229