Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38973 risultati

News
NVIDIA Patches High-Severity Flaws Threatening Jetson Edge AI Systems

NVIDIA Patches High-Severity Flaws Threatening Jetson Edge AI Systems NVIDIA has issued a software update for its Jetson Linux platform to address several security flaws that could leave edge AI and autonomous systems exposed. The vulnerabilities range from high-severit ... Read more Published Date: Apr 02, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom02 apr 2026
VulnerabilitàAlta
CVE-2026-2737 - Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web application

CVE ID :CVE-2026-2737 Published : April 2, 2026, 1:28 p.m. | 26 minutes ago Description :A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-3692 - Unintended command execution during report generation in Progress Flowmon

CVE ID :CVE-2026-3692 Published : April 2, 2026, 1:27 p.m. | 26 minutes ago Description :In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-4636 (CVSS 8.1)

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-4634 (CVSS 7.5)

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-5331 - OpenCart Extension Installer installer.php path traversal

CVE ID :CVE-2026-5331 Published : April 2, 2026, 1:16 p.m. | 38 minutes ago Description :A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the component Extension Installer Page. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-5330 - SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control

CVE ID :CVE-2026-5330 Published : April 2, 2026, 1:16 p.m. | 38 minutes ago Description :A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in improper access controls. The attack may be initiated remotely. The exploit has been made public and could be used. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-5328 - shsuishang modulithshop ProductItemDao ProductIndexServiceImpl.java listItem sql injection

CVE ID :CVE-2026-5328 Published : April 2, 2026, 1:16 p.m. | 38 minutes ago Description :A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted element is the function listItem of the file src/main/java/com/suisung/shopsuite/pt/service/impl/ProductIndexServiceImpl.java of the component ProductItemDao Interface. Executing a manipulation of the argument sidx/sort can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This patch is called 42bcb9463425d1be906c3b290cf29885eb5a2324. A patch should be applied to remediate this issue. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-4282 (CVSS 7.4)

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-3872 (CVSS 7.3)

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-4325 - Keycloak: keycloak: replay of action tokens via improper handling of single-use entries

CVE ID :CVE-2026-4325 Published : April 2, 2026, 1:16 p.m. | 38 minutes ago Description :A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This could lead to unauthorized access or account compromise. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-34890 - WordPress MSTW League Manager plugin <= 2.10 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-34890 Published : April 2, 2026, 1:16 p.m. | 38 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MSTW League Manager allows DOM-Based XSS.This issue affects MSTW League Manager: from n/a through 2.10. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026

Pagina 2490 di 3248

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.