Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

39765 risultati

VulnerabilitàAlta
CVE-2026-27663 - "CPCI85 and RTUM85 Denial-of-Service Vulnerability"

CVE ID :CVE-2026-27663 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-26072 - EVerest has race-condition-induced std::map corruption in OCPP 1.6 evse_soc_map

CVE ID :CVE-2026-26072 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map` concurrent access (container/optional corruption possible). The trigger is EV SoC update with powermeter periodic update and unplugging/SessionFinished status. Version 2026.02.0 patches the issue. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-26071 - EVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Use‑After‑Free

CVE ID :CVE-2026-26071 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurrent access. with heap-use-after-free possible. This is triggered by EVCCID update (EV/ISO15118) and OCPP session/authorization events. Version 2026.02.0 contains a patch. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-26070 - EVerest: OCPP 2.0.1 EV SoC Update Race Causes Charge Point Crash

CVE ID :CVE-2026-26070 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map` concurrent access (container/optional corruption possible). The trigger is an EV SoC update with powermeter periodic update and unplugging/SessionFinished state. Version 2026.2.0 contains a patch. Severity: 4.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-26008 - EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferModes

CVE ID :CVE-2026-26008 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/memory corruption. This is because the CSMS sends UpdateAllowedEnergyTransferModes over the network. Version 2026.2.0 contains a patch. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-23995 - EVerest has stack buffer overflow in ifreq.ifr_name when interface name exceeds IFNAMSIZ

CVE ID :CVE-2026-23995 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer than IFNAMSIZ (16) to CAN open routines overflows `ifreq.ifr_name`, corrupting adjacent stack data and enabling potential code execution. A malicious or misconfigured interface name can trigger this before any privilege checks. Version 2026.02.0 contains a patch. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-22790 - EVerest's unchecked SLAC payload length causes stack overflow in HomeplugMessage::setup_payload

CVE ID :CVE-2026-22790 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release builds the check is removed, so oversized SLAC payloads are `memcpy`'d into a ~1497-byte stack buffer, corrupting the stack and enabling remote code execution from network-provided frames. Version 2026.02.0 contains a patch. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-22593 - EVerest has off-by-one stack buffer overflow in IsoMux certificate filename parsing

CVE ID :CVE-2026-22593 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename handling causes a stack-based buffer overflow when a filename length equals `MAX_FILE_NAME_LENGTH` (100). A crafted filename in the certificate directory can overflow `file_names[idx]`, corrupting stack state and enabling potential code execution. Version 2026.02.0 contains a patch. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
News
High-Severity strongSwan Flaw Enables Remote VPN Gateway Crashes

High-Severity strongSwan Flaw Enables Remote VPN Gateway Crashes A high-severity security vulnerability has been uncovered in strongSwan, the widely used open-source IPsec-based VPN solution. The flaw, tracked as CVE-2026-25075 with a CVSSv4 score of 8.7, resides i ... Read more Published Date: Mar 26, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-23921 CVE-2026-25075 CVE-2026-3584 CVE-2026-0229 CVE-2025-29969 CVE-2023-41913

CVEfeed Newsroom26 mar 2026
VulnerabilitàAlta
CVE-2026-4877 - itsourcecode Payroll Management System index.php cross site scripting

CVE ID :CVE-2026-4877 Published : March 26, 2026, 2:16 p.m. | 1 hour, 36 minutes ago Description :A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-4876 - itsourcecode Free Hotel Reservation System index.php sql injection

CVE ID :CVE-2026-4876 Published : March 26, 2026, 2:16 p.m. | 1 hour, 36 minutes ago Description :A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_amenities/index.php?view=editpic. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-2511 (CVSS 7.5)

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()` without enclosing the result in quotes in the SQL query, rendering the escaping ineffective against payloads that do not contain quote characters. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)26 mar 2026

Pagina 2658 di 3314

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.