Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38841 risultati

VulnerabilitàAlta
CVE-2026-34783 - Ferret has a Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites

CVE ID :CVE-2026-34783 Published : April 6, 2026, 5:17 p.m. | 38 minutes ago Description :Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library function allows a malicious website to write arbitrary files to the filesystem of the machine running Ferret. When an operator scrapes a website that returns filenames containing ../ sequences, and uses those filenames to construct output paths (a standard scraping pattern), the attacker controls both the destination path and the file content. This can lead to remote code execution via cron jobs, SSH authorized_keys, shell profiles, or web shells. This vulnerability is fixed in 2.0.0-alpha.4. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 apr 2026
VulnerabilitàAlta
CVE-2026-34841 - Axios npm Supply Chain Incident Impacting @usebruno/cli

CVE ID :CVE-2026-34841 Published : April 6, 2026, 5:17 p.m. | 38 minutes ago Description :Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026 may have been impacted. Upgrade to 3.2.1 Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 apr 2026
VulnerabilitàAlta
CVE-2026-31313 - Feehi CMS Stored XSS Vulnerability

CVE ID :CVE-2026-31313 Published : April 6, 2026, 5:17 p.m. | 38 minutes ago Description :An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Content field. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 apr 2026
VulnerabilitàAlta
CVE-2026-5671 - Cyber-III Student-Management-System Class Schedule Deletion Endpoint delete_batch.php cross site scripting

CVE ID :CVE-2026-5671 Published : April 6, 2026, 5:15 p.m. | 40 minutes ago Description :A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Impacted is an unknown function of the file /admin/class%20schedule/delete_batch.php of the component Class Schedule Deletion Endpoint. Executing a manipulation of the argument batch can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 apr 2026
News
CISA Warns of Fortinet 0-Day Vulnerability Actively Exploited in Attacks

CISA Warns of Fortinet 0-Day Vulnerability Actively Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-35616, a critical improper access control vulnerability in Fortinet FortiClient Enterprise Management Server (EMS), ... Read more Published Date: Apr 06, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616

CVEfeed Newsroom06 apr 2026
News
The 24-Hour Blitz: Storm-1175 Weaponizes Zero-Days for High-Velocity Ransomware

The 24-Hour Blitz: Storm-1175 Weaponizes Zero-Days for High-Velocity Ransomware Storm-1175 attack chain | Image: Microsoft A new report from Microsoft Threat Intelligence has exposured on Storm-1175, a financially motivated threat actor that has mastered the art of the high-veloc ... Read more Published Date: Apr 06, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom06 apr 2026
News
The Ninja’s Open Door: How a 9.8 CVSS Flaw Grants Hackers Full Control of 50,000 WordPress Sites

The Ninja’s Open Door: How a 9.8 CVSS Flaw Grants Hackers Full Control of 50,000 WordPress Sites In a major alert for the WordPress community, a critical security flaw has been disclosed in the Ninja Forms – File Upload plugin. The vulnerability, tracked as CVE-2026-0740, carries a CVSS score of ... Read more Published Date: Apr 06, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom06 apr 2026
VulnerabilitàAlta
CVE-2026-5665 (CVSS 7.3)

A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/checklogin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

NVD (NIST)06 apr 2026
VulnerabilitàAlta
CVE-2026-21382 (CVSS 7.8)

Memory Corruption when handling power management requests with improperly sized input/output buffers.

NVD (NIST)06 apr 2026
VulnerabilitàAlta
CVE-2026-21381 (CVSS 7.6)

Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.

NVD (NIST)06 apr 2026
VulnerabilitàAlta
CVE-2026-21380 (CVSS 7.8)

Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.

NVD (NIST)06 apr 2026
VulnerabilitàAlta
CVE-2026-21378 (CVSS 7.8)

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

NVD (NIST)06 apr 2026

Pagina 2423 di 3237

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.