Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38973 risultati

VulnerabilitàAlta
CVE-2026-34794 (CVSS 8.8)

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-34793 (CVSS 8.8)

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-34792 (CVSS 8.8)

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-34791 (CVSS 8.8)

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-34790 (CVSS 7.1)

Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, which is then passed to an unlink() call.

NVD (NIST)02 apr 2026
News
Software supply chain hacks trigger wave of intrusions, data theft

Software supply chain hacks trigger wave of intrusions, data theft After linking the Axios npm supply chain attack to North Korean hackers, Google researchers warned that “hundreds of thousands of stolen secrets could potentially be circulating” as a result of this a ... Read more Published Date: Apr 02, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5281 CVE-2026-33634

CVEfeed Newsroom02 apr 2026
News
CISA Warns of Chrome 0-Day Vulnerability Actively Exploited in Attacks

CISA Warns of Chrome 0-Day Vulnerability Actively Exploited in Attacks A critical warning has been issued over a newly discovered zero-day vulnerability in Google Chrome, raising serious concerns for users worldwide. This flaw is actively exploited in the wild, allowing ... Read more Published Date: Apr 02, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5281

CVEfeed Newsroom02 apr 2026
News
Lodash Patches High-Severity Code Injection Vulnerability

Lodash Patches High-Severity Code Injection Vulnerability In the world of modern JavaScript, Lodash is the undisputed heavyweight champion of utility libraries, providing the modularity and performance that millions of developers rely on daily. However, a ne ... Read more Published Date: Apr 02, 2026 (1 day, 12 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom02 apr 2026
VulnerabilitàAlta
CVE-2026-5334 (CVSS 7.3)

A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=edit&id=3 of the component Parameter Handler. This manipulation of the argument deptid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-5333 (CVSS 7.3)

A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)02 apr 2026
News
vSphere and BRICKSTORM Malware: A Defender's Guide

vSphere and BRICKSTORM Malware: A Defender's Guide Written by: Stuart Carrera Introduction Building on recent BRICKSTORM research from Google Threat Intelligence Group (GTIG), this post explores the evolving threats facing virtualized environments. Th ... Read more Published Date: Apr 02, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22769

CVEfeed Newsroom02 apr 2026
VulnerabilitàAlta
CVE-2026-5333 - DefaultFuction Content-Management-System tools.php command injection

CVE ID :CVE-2026-5333 Published : April 2, 2026, 1:30 p.m. | 24 minutes ago Description :A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026

Pagina 2489 di 3248

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.