Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

39376 risultati

VulnerabilitàAlta
CVE-2026-0558 - Unauthenticated File Upload in parisneo/lollms

CVE ID :CVE-2026-0558 Published : March 29, 2026, 6:16 p.m. | 15 hours, 37 minutes ago Description :A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other file-related endpoints, and lacks the `Depends(get_current_active_user)` dependency. This issue can lead to denial of service (DoS) through resource exhaustion, information disclosure, and violation of the application's documented security policies. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
VulnerabilitàAlta
CVE-2026-34005 - Xiongmai DVR/NVR Command Injection Vulnerability

CVE ID :CVE-2026-34005 Published : March 29, 2026, 5:16 p.m. | 14 hours, 37 minutes ago Description :In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
News
SQL to SSH: Critical 9.1 CVSS RCE in Grafana Turns Monitoring into a Remote Hijack

SQL to SSH: Critical 9.1 CVSS RCE in Grafana Turns Monitoring into a Remote Hijack The Grafana team has released an urgent security advisory following the discovery of two significant vulnerabilities that could allow attackers to hijack servers or crash instances. The release of Gra ... Read more Published Date: Mar 29, 2026 (1 day, 16 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-27880 CVE-2026-27876 CVE-2026-27728 CVE-2022-29170

CVEfeed Newsroom29 mar 2026
VulnerabilitàAlta
CVE-2026-5046 (CVSS 8.8)

A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component Parameter Handler. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

NVD (NIST)29 mar 2026
VulnerabilitàAlta
CVE-2026-5046 - Tenda FH1201 Parameter WrlExtraSet formWrlExtraSet stack-based overflow

CVE ID :CVE-2026-5046 Published : March 29, 2026, 3:16 p.m. | 16 hours, 37 minutes ago Description :A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component Parameter Handler. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
VulnerabilitàAlta
CVE-2026-5045 (CVSS 8.8)

A vulnerability was detected in Tenda FH1201 1.2.0.14(408). This impacts the function WrlclientSet of the file /goform/WrlclientSet of the component Parameter Handler. Performing a manipulation of the argument GO results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

NVD (NIST)29 mar 2026
VulnerabilitàAlta
CVE-2026-5044 (CVSS 8.8)

A security vulnerability has been detected in Belkin F9K1122 1.00.33. This affects the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler. Such manipulation of the argument webpage leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)29 mar 2026
VulnerabilitàAlta
CVE-2026-33575 (CVSS 7.5)

OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes from chat history, logs, or screenshots can recover and reuse the shared gateway credential outside the intended one-time pairing flow.

NVD (NIST)29 mar 2026
VulnerabilitàAlta
CVE-2026-5044 - Belkin F9K1122 Setting formSetSystemSettings stack-based overflow

CVE ID :CVE-2026-5044 Published : March 29, 2026, 1:17 p.m. | 18 hours, 36 minutes ago Description :A security vulnerability has been detected in Belkin F9K1122 1.00.33. This affects the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler. Such manipulation of the argument webpage leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
VulnerabilitàAlta
CVE-2026-33575 - OpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup Codes

CVE ID :CVE-2026-33575 Published : March 29, 2026, 1:17 p.m. | 18 hours, 36 minutes ago Description :OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes from chat history, logs, or screenshots can recover and reuse the shared gateway credential outside the intended one-time pairing flow. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
VulnerabilitàAlta
CVE-2026-33574 - OpenClaw < 2026.3.8 - Path Traversal via Tools Root Rebinding in Skills Download

CVE ID :CVE-2026-33574 Published : March 29, 2026, 1:17 p.m. | 16 hours, 36 minutes ago Description :OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the tools root lexically but reuses the mutable path during archive download and copy operations. A local attacker can rebind the tools-root path between validation and final write to redirect the installer outside the intended tools directory. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
VulnerabilitàAlta
CVE-2026-33573 (CVSS 8.8)

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries by supplying attacker-controlled spawnedBy and workspaceDir values. Remote operators can escape the configured workspace boundary and execute arbitrary file and exec operations from any process-accessible directory.

NVD (NIST)29 mar 2026

Pagina 2585 di 3282

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.