Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45612 risultati

VulnerabilitàAlta
CVE-2026-94540 (CVSS 7.7)

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-94535 (CVSS 7.1)

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to permanently remove notifications belonging to other users without recipient validation.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-94534 (CVSS 7.1)

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodies to rewrite profile fields including nickname, ID card, sex, nation, education, work description, and avatar attachments of other users.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-94622 - vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata

CVE ID :CVE-2026-94622 Published : Sept. 21, 2026, 10:17 p.m. | 8 hours, 10 minutes ago Description :vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigger an uncaught KeyError in EngineCore scheduling, causing the decode engine to terminate and making all routed requests fail until manual restart. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94540 - DesktopSMS 1.11.0 Unauthorized Access via Local Service

CVE ID :CVE-2026-94540 Published : Sept. 21, 2026, 10:17 p.m. | 8 hours, 10 minutes ago Description :DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform privileged SMS operations using the victim application's permissions. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94534 - lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints

CVE ID :CVE-2026-94534 Published : Sept. 21, 2026, 10:17 p.m. | 6 hours, 13 minutes ago Description :lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodies to rewrite profile fields including nickname, ID card, sex, nation, education, work description, and avatar attachments of other users. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94535 - lamp-cloud through 5.10.0 Unauthorized Notification Deletion

CVE ID :CVE-2026-94535 Published : Sept. 21, 2026, 10:17 p.m. | 6 hours, 13 minutes ago Description :lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to permanently remove notifications belonging to other users without recipient validation. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94536 - lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource

CVE ID :CVE-2026-94536 Published : Sept. 21, 2026, 10:17 p.m. | 6 hours, 13 minutes ago Description :lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can supply arbitrary employeeId values to enumerate other employees' role codes, permission codes, and complete front-end router trees without authorization checks. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94532 - lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById

CVE ID :CVE-2026-94532 Published : Sept. 21, 2026, 10:17 p.m. | 4 hours, 5 minutes ago Description :lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensitive user information including mobile numbers, email addresses, national identity card numbers, and WeChat and DingTalk OpenIDs. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94533 - lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file

CVE ID :CVE-2026-94533 Published : Sept. 21, 2026, 10:17 p.m. | 6 hours, 13 minutes ago Description :lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files by supplying valid attachment identifiers to the /anyone/file/down and /anyone/file/download endpoints, as the application never validates file ownership against the created_by column. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-93340 - Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint

CVE ID :CVE-2026-93340 Published : Sept. 21, 2026, 10:16 p.m. | 4 hours, 5 minutes ago Description :Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a crafted request specifying an attacker-controlled origin, causing the victim to receive a poisoned reset link that discloses the session token to the attacker, enabling full account takeover including administrator accounts. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-79079 - CrossWire Xiphos Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-79079 Published : Sept. 21, 2026, 10:16 p.m. | 2 hours, 3 minutes ago Description :An issue in CrossWire Xiphos Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026

Pagina 264 di 3801

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.