Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

42023 risultati

VulnerabilitàAlta
CVE-2026-33323 - Parse Server: Email verification resend page leaks user existence

CVE ID :CVE-2026-33323 Published : March 24, 2026, 7:16 p.m. | 35 minutes ago Description :Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email verification links return distinguishable responses depending on whether the provided username exists and has an unverified email. This allows an unauthenticated attacker to enumerate valid usernames by observing different redirect targets. The existing emailVerifySuccessOnInvalidEmail configuration option, which is enabled by default and protects the API route against this, did not apply to these routes. This issue has been patched in versions 8.6.51 and 9.6.0-alpha.40. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-30932 - Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API

CVE ID :CVE-2026-30932 Published : March 24, 2026, 7:16 p.m. | 35 minutes ago Description :Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. $INCLUDE) into the zone file that gets written to disk when the DNS rebuild cron job runs. This issue has been patched in version 2.3.5. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-29772 - Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

CVE ID :CVE-2026-29772 Published : March 24, 2026, 7:16 p.m. | 35 minutes ago Description :Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates a V8 heap object for every element in the input, a crafted payload of many small JSON objects achieves ~15x memory amplification (wire bytes to heap bytes), allowing a single unauthenticated request to exhaust the process heap and crash the server. The /_server-islands/[name] route is registered on all Astro SSR apps regardless of whether any component uses server:defer, and the body is parsed before the island name is validated, so any Astro SSR app with the Node standalone adapter is affected. This issue has been patched in version 10.0.0. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-2417 - Missing Authentication for Critical Function in Pharos Controls Mosaic Show Controller

CVE ID :CVE-2026-2417 Published : March 24, 2026, 7:16 p.m. | 35 minutes ago Description :A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-23923 - Unauthenticated arbitrary PHP class instantiation

CVE ID :CVE-2026-23923 Published : March 24, 2026, 7:16 p.m. | 35 minutes ago Description :An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-23924 - Agent 2 Docker plugin arbitrary file read via Docker API injection

CVE ID :CVE-2026-23924 Published : March 24, 2026, 7:16 p.m. | 35 minutes ago Description :Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
News
Dell Wyse Management Vulnerabilities Enables Complete System Compromise

Dell Wyse Management Vulnerabilities Enables Complete System Compromise A recent security analysis has revealed how chaining seemingly minor logic flaws in Dell Wyse Management Suite (WMS) On-Premises can result in a complete system compromise. Security researchers demons ... Read more Published Date: Mar 24, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22766 CVE-2026-22765

CVEfeed Newsroom24 mar 2026
VulnerabilitàAlta
CVE-2026-33162 - Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions

CVE ID :CVE-2026-33162 Published : March 24, 2026, 5:32 p.m. | 20 minutes ago Description :Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either source or destination section. This issue has been patched in version 5.9.14. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-32854 - LibVNCServer httpd proxy NULL Pointer Dereference

CVE ID :CVE-2026-32854 Published : March 24, 2026, 5:31 p.m. | 21 minutes ago Description :LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploit missing validation of strchr() return values in the CONNECT and GET proxy handling paths to trigger null pointer dereferences and crash the server when httpd and proxy features are enabled. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-33161 - Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users

CVE ID :CVE-2026-33161 Published : March 24, 2026, 5:31 p.m. | 21 minutes ago Description :Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive editor response data, including focalPoint. The endpoint returns private editing metadata without per-asset authorization validation. This issue has been patched in versions 4.17.8 and 5.9.14. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-32853 - LibVNCServer UltraZip Encoding Heap Out-of-bounds Read

CVE ID :CVE-2026-32853 Published : March 24, 2026, 5:30 p.m. | 22 minutes ago Description :LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a malicious VNC server to cause information disclosure or application crash. Attackers can exploit improper bounds checking in the HandleUltraZipBPP() function by manipulating subrectangle header counts to read beyond the allocated heap buffer. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-33160 - Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL

CVE ID :CVE-2026-33160 Published : March 24, 2026, 5:30 p.m. | 22 minutes ago Description :Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid transform URL, and fetch transformed image bytes. The endpoint is anonymous and does not enforce per-asset authorization before returning the transform URL. This issue has been patched in versions 4.17.8 and 5.9.14. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026

Pagina 2880 di 3502

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.