Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

40238 risultati

News
Critical 9.4 CVSS Flaw Exposes Harbor Registries to Total Hijack

Critical 9.4 CVSS Flaw Exposes Harbor Registries to Total Hijack The CERT Coordination Center (CERT/CC) has issued a critical security warning regarding GoHarbor’s Harbor, a widely used open-source container registry. The vulnerability, tracked as CVE-2026-4404 wit ... Read more Published Date: Mar 25, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-15517 CVE-2026-4404

CVEfeed Newsroom25 mar 2026
VulnerabilitàAlta
CVE-2026-3608 (CVSS 7.5)

Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.

NVD (NIST)25 mar 2026
VulnerabilitàAlta
CVE-2026-32326 - SHARP Routers Authentication Bypass Vulnerability

CVE ID :CVE-2026-32326 Published : March 25, 2026, 8:16 a.m. | 1 hour, 36 minutes ago Description :SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
News
Dutch Finance Ministry Investigates Data Breach in Internal Systems

Dutch Finance Ministry Investigates Data Breach in Internal Systems The Ministry of Finance cyberattack in the Netherlands has once again highlighted a growing concern: even critical government systems are struggling to stay ahead of increasingly advanced threats. Whi ... Read more Published Date: Mar 25, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-21992 CVE-2025-4428 CVE-2025-4427

CVEfeed Newsroom25 mar 2026
VulnerabilitàAlta
CVE-2026-26306 - OM Workspace DLL Loading Vulnerability

CVE ID :CVE-2026-26306 Published : March 25, 2026, 6:16 a.m. | 3 hours, 36 minutes ago Description :The installer for OM Workspace (Windows Edition) Ver 2.4 and earlier insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute arbitrary code with the privileges of the user invoking the installer. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
VulnerabilitàAlta
CVE-2026-2343 - PeproDev Ultimate Invoice <= 2.2.5 - Unauthenticated Invoice Archive Download

CVE ID :CVE-2026-2343 Published : March 25, 2026, 6:16 a.m. | 3 hours, 36 minutes ago Description :The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
News
Streaming Nightmare: Unpatched CVSS 10.0 Flaws Leave AVideo Servers Wide Open

Streaming Nightmare: Unpatched CVSS 10.0 Flaws Leave AVideo Servers Wide Open AVideo, a popular streaming platform used by creators and businesses to manage and monetize video content, is facing a severe security crisis. Researchers have identified five critical vulnerabilities ... Read more Published Date: Mar 25, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33716 CVE-2025-15517 CVE-2026-33502 CVE-2026-33478 CVE-2026-33352 CVE-2026-33351 CVE-2026-28501

CVEfeed Newsroom25 mar 2026
VulnerabilitàAlta
CVE-2026-33253 - SANYO DENKI CO., LTD. SANUPS SOFTWARE Privilege Escalation Vulnerability

CVE ID :CVE-2026-33253 Published : March 25, 2026, 6:16 a.m. | 3 hours, 36 minutes ago Description :SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
VulnerabilitàAlta
CVE-2026-2072 - Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer

CVE ID :CVE-2026-2072 Published : March 25, 2026, 3:16 a.m. | 6 hours, 36 minutes ago Description :Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
VulnerabilitàAlta
CVE-2026-1166 - Open Redirect Vulnerability in Hitachi Ops Center Administrator

CVE ID :CVE-2026-1166 Published : March 25, 2026, 3:16 a.m. | 6 hours, 36 minutes ago Description :Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
VulnerabilitàAlta
CVE-2026-4784 (CVSS 7.3)

A vulnerability was found in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /checkcheckout.php of the component Parameter Handler. The manipulation of the argument serviceId results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

NVD (NIST)25 mar 2026
VulnerabilitàAlta
CVE-2026-4784 - code-projects Simple Laundry System Parameter checkcheckout.php sql injection

CVE ID :CVE-2026-4784 Published : March 25, 2026, 2:16 a.m. | 7 hours, 36 minutes ago Description :A vulnerability was found in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /checkcheckout.php of the component Parameter Handler. The manipulation of the argument serviceId results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026

Pagina 2724 di 3354

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.