Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38911 risultati

VulnerabilitàAlta
CVE-2026-35549 - MariaDB Server Caching Sha2 Password Authentication Plugin Crash Vulnerability

CVE ID :CVE-2026-35549 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-5453 - Rico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded key

CVE ID :CVE-2026-5453 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processing of the file br/com/rico/mobile/di/SegmentSettingsModule.java of the component br.com.rico.mobile. Such manipulation of the argument SEGMENT_WRITE_KEY leads to use of hard-coded cryptographic key . The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35543 - Roundcube Webmail SVG Image Injection Vulnerability

CVE ID :CVE-2026-35543 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35540 - Roundcube Webmail CSS Injection Vulnerability

CVE ID :CVE-2026-35540 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35542 - Roundcube Webmail Background Attribute Injection Vulnerability

CVE ID :CVE-2026-35542 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35544 - Roundcube Webmail CSS Injection Vulnerability

CVE ID :CVE-2026-35544 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35545 - Roundcube Webmail SVG Animate Element Injection Vulnerability

CVE ID :CVE-2026-35545 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35541 - Roundcube Webmail Password Comparison Type Confusion Vulnerability

CVE ID :CVE-2026-35541 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35539 - Roundcube Webmail Cross-Site Scripting Vulnerability

CVE ID :CVE-2026-35539 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35538 - Roundcube Webmail IMAP Injection/CSRF Bypass

CVE ID :CVE-2026-35538 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35537 - "Roundcube Webmail Deserialization File Write Vulnerability"

CVE ID :CVE-2026-35537 Published : April 3, 2026, 4:17 a.m. | 7 hours, 37 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
News
Smart Home Alert: Critical Flaws Exposed in TP-Link Tapo Security Cameras

Smart Home Alert: Critical Flaws Exposed in TP-Link Tapo Security Cameras A security advisory from TP-Link have exposured a series of high-severity vulnerabilities—ranging from CVE-2026-34118 to CVE-2026-34124—affecting the Tapo C520WS v2.6 outdoor security camera. With CVS ... Read more Published Date: Apr 03, 2026 (2 days, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34124 CVE-2026-34122 CVE-2026-34121 CVE-2026-34118 CVE-2026-5281 CVE-2026-3502 CVE-2026-33032 CVE-2025-15568 CVE-2025-9520 CVE-2025-14756 CVE-2026-21962 CVE-2026-0629 CVE-2025-6542 CVE-2025-58364 CVE-2025-58060

CVEfeed Newsroom03 apr 2026

Pagina 2472 di 3243

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.