Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

39765 risultati

News
Cisco Alert: Public Vulnerabilities in IOS XE Risk Service Denial and Privilege Escalation

Cisco Alert: Public Vulnerabilities in IOS XE Risk Service Denial and Privilege Escalation Cisco has issued important security advisories for two distinct vulnerabilities within its Cisco IOS XE Software, targeting the Command Line Interface (CLI) and the Lobby Ambassador management API. Th ... Read more Published Date: Mar 26, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20114 CVE-2026-20110 CVE-2026-20045 CVE-2025-20363 CVE-2025-20352 CVE-2025-29969 CVE-2024-20401

CVEfeed Newsroom26 mar 2026
VulnerabilitàAlta
CVE-2026-4861 (CVSS 8.8)

A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /cgi-bin/nas.cgi. This manipulation of the argument Content-Length causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2026-4860 (CVSS 7.3)

A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/RedisTemplateConfig.java of the component API Endpoint. The manipulation results in deserialization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2026-4860 - 648540858 wvp-GB28181-pro API Endpoint RedisTemplateConfig.java GenericFastJsonRedisSerializer deserialization

CVE ID :CVE-2026-4860 Published : March 26, 2026, 9:16 a.m. | 2 hours, 36 minutes ago Description :A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/RedisTemplateConfig.java of the component API Endpoint. The manipulation results in deserialization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-4861 - Wavlink WL-NU516U1 nas.cgi ftext stack-based overflow

CVE ID :CVE-2026-4861 Published : March 26, 2026, 9:16 a.m. | 2 hours, 36 minutes ago Description :A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /cgi-bin/nas.cgi. This manipulation of the argument Content-Length causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-4263 - Incorrect authorization in HiJiffy Chatbot

CVE ID :CVE-2026-4263 Published : March 26, 2026, 10:16 a.m. | 1 hour, 36 minutes ago Description :Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'visitor' in '/api/v1/webchat/message'. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
News
Britse overheid roept organisaties op om kritiek Citrix-lek meteen te patchen

Britse overheid roept organisaties op om kritiek Citrix-lek meteen te patchen De Britse overheid heeft organisaties opgeroepen om een kritieke kwetsbaarheid in Citrix NetScaler ADC en Citrix NetScaler meteen te patchen. Beveiligingsupdates voor het probleem, aangeduid als CVE-2 ... Read more Published Date: Mar 26, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-3055

CVEfeed Newsroom26 mar 2026
VulnerabilitàAlta
CVE-2026-4262 - Incorrect authorization in HiJiffy Chatbot

CVE ID :CVE-2026-4262 Published : March 26, 2026, 10:16 a.m. | 1 hour, 36 minutes ago Description :Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'ID' in '/api/v1/download//'. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-4862 - UTT HiPER 1250GW Parameter formConfigDnsFilterGlobal strcpy buffer overflow

CVE ID :CVE-2026-4862 Published : March 26, 2026, 9 a.m. | 52 minutes ago Description :A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file /goform/formConfigDnsFilterGlobal of the component Parameter Handler. Such manipulation of the argument GroupName leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
News
Node.js Fixes Critical Flaws, Patches DoS Risk in Latest Security Update

Node.js Fixes Critical Flaws, Patches DoS Risk in Latest Security Update The Node.js project has issued a series of security updates addressing multiple vulnerabilities across its active release lines. The update covers versions in the 20.x, 22.x, 24.x, and 25.x branches, ... Read more Published Date: Mar 26, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom26 mar 2026
VulnerabilitàAlta
CVE-2026-4850 (CVSS 7.3)

A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checkregisitem.php of the component Parameter Handler. The manipulation of the argument Long-arm-shirtVol results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2026-4849 - code-projects Simple Laundry System Parameter modify.php cross site scripting

CVE ID :CVE-2026-4849 Published : March 26, 2026, 8:16 a.m. | 3 hours, 36 minutes ago Description :A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component Parameter Handler. The manipulation of the argument firstName leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026

Pagina 2664 di 3314

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.