Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

40130 risultati

VulnerabilitàAlta
CVE-2026-30162 - Timo XSS

CVE ID :CVE-2026-30162 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-29933 - YZMCMS Reflected XSS

CVE ID :CVE-2026-29933 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referrer value in the request header. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-27664 (CVSS 7.5)

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). The affected application contains an out-of-bounds write vulnerability while parsing specially crafted XML inputs. This could allow an unauthenticated attacker to exploit this issue by sending a malicious XML request, which may cause the service to crash, resulting in a denial-of-service condition.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2026-28298 - SolarWinds Observability Self-Hosted Stored Cross-Site Scripting Vulnerability

CVE ID :CVE-2026-28298 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-28297 - SolarWinds Observability Self-Hosted Stored Cross-Site Scripting Vulnerability

CVE ID :CVE-2026-28297 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-27663 - "CPCI85 and RTUM85 Denial-of-Service Vulnerability"

CVE ID :CVE-2026-27663 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-26072 - EVerest has race-condition-induced std::map corruption in OCPP 1.6 evse_soc_map

CVE ID :CVE-2026-26072 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map` concurrent access (container/optional corruption possible). The trigger is EV SoC update with powermeter periodic update and unplugging/SessionFinished status. Version 2026.02.0 patches the issue. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-26071 - EVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Use‑After‑Free

CVE ID :CVE-2026-26071 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurrent access. with heap-use-after-free possible. This is triggered by EVCCID update (EV/ISO15118) and OCPP session/authorization events. Version 2026.02.0 contains a patch. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-26070 - EVerest: OCPP 2.0.1 EV SoC Update Race Causes Charge Point Crash

CVE ID :CVE-2026-26070 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map` concurrent access (container/optional corruption possible). The trigger is an EV SoC update with powermeter periodic update and unplugging/SessionFinished state. Version 2026.2.0 contains a patch. Severity: 4.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-26008 - EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferModes

CVE ID :CVE-2026-26008 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/memory corruption. This is because the CSMS sends UpdateAllowedEnergyTransferModes over the network. Version 2026.2.0 contains a patch. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-23995 - EVerest has stack buffer overflow in ifreq.ifr_name when interface name exceeds IFNAMSIZ

CVE ID :CVE-2026-23995 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer than IFNAMSIZ (16) to CAN open routines overflows `ifreq.ifr_name`, corrupting adjacent stack data and enabling potential code execution. A malicious or misconfigured interface name can trigger this before any privilege checks. Version 2026.02.0 contains a patch. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-22790 - EVerest's unchecked SLAC payload length causes stack overflow in HomeplugMessage::setup_payload

CVE ID :CVE-2026-22790 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release builds the check is removed, so oversized SLAC payloads are `memcpy`'d into a ~1497-byte stack buffer, corrupting the stack and enabling remote code execution from network-provided frames. Version 2026.02.0 contains a patch. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026

Pagina 2688 di 3345

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.