Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

39746 risultati

VulnerabilitàAlta
CVE-2026-4948 - Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization

CVE ID :CVE-2026-4948 Published : March 27, 2026, 6:16 a.m. | 7 hours, 36 minutes ago Description :A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-22744 - Spring AI Redis Store Unescaped User-Controlled Input in TAG Field

CVE ID :CVE-2026-22744 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-32669 - BUFFALO Wi-Fi Router Code Injection Vulnerability

CVE ID :CVE-2026-32669 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-27650 - Buffalo Wi-Fi Router OS Command Injection Vulnerability

CVE ID :CVE-2026-27650 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-32678 - Buffalo Wi-Fi Router Authentication Bypass Vulnerability

CVE ID :CVE-2026-32678 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without authentication. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-33280 - Buffalo Wi-Fi Router OS Command Injection Vulnerability

CVE ID :CVE-2026-33280 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-33366 - BUFFALO Wi-Fi Router Unauthenticated Reboot Vulnerability

CVE ID :CVE-2026-33366 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-22742 - Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching

CVE ID :CVE-2026-22742 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended internal or external destinations. This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-22743 - Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore

CVE ID :CVE-2026-22743 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() embeds the key into a backtick-delimited Cypher property accessor (node.`metadata.`) after stripping only double quotes, without escaping embedded backticks.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2024-14028 - Multiple implicit reads in parallel can result in a crash or denial of service

CVE ID :CVE-2024-14028 Published : March 27, 2026, 6:16 a.m. | 3 hours, 36 minutes ago Description :Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.31 smartLink HW-PN: before 1.02. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-22738 - SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution

CVE ID :CVE-2026-22738 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key are affected. This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-33559 - WordPress Plugin "OpenStreetMap" Cross-Site Scripting (XSS)

CVE ID :CVE-2026-33559 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim user accesses this page, the script may be executed in the user's web browser. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026

Pagina 2643 di 3313

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.