Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45464 risultati

VulnerabilitàAlta
CVE-2019-25626 - River Past Cam Do 3.7.6 Local Buffer Overflow in Activation Code

CVE ID :CVE-2019-25626 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbitrary code by supplying a malicious activation code string. Attackers can craft a buffer containing 608 bytes of junk data followed by shellcode and SEH chain overwrite values to trigger code execution when the activation dialog processes the input. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2025-64998 - Session hijacking via exposed session signing secret in distributed Checkmk setups

CVE ID :CVE-2025-64998 Published : March 24, 2026, 11:25 a.m. | 26 minutes ago Description :Exposure of session signing secret in Checkmk Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
News
Checkmarx Alert: Malicious Plugins and GitHub Actions Hit OpenVSX in New Supply Chain Attack

Checkmarx Alert: Malicious Plugins and GitHub Actions Hit OpenVSX in New Supply Chain Attack Today, security firm Checkmarx has identified a recent supply chain security incident. The breach involved the publication of malicious versions of two popular security plugins to the OpenVSX registry ... Read more Published Date: Mar 24, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-21509 CVE-2025-32432

CVEfeed Newsroom24 mar 2026
News
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials

TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials Two more GitHub Actions workflows have become the latest to be compromised by credential-stealing malware by a threat actor known as TeamPCP, the cloud-native cybercriminal operation also behind the T ... Read more Published Date: Mar 24, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33634

CVEfeed Newsroom24 mar 2026
News
Oracle Issues Emergency Patch for Critical Flaw Enabling Remote Code Execution

Oracle Issues Emergency Patch for Critical Flaw Enabling Remote Code Execution Oracle has released an emergency out‑of‑band patch to address a critical vulnerability, tracked as CVE‑2026‑21992, that affects two core enterprise products: Oracle Identity Manager and Oracle Web Ser ... Read more Published Date: Mar 24, 2026 (1 day, 15 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-21992 CVE-2026-22778 CVE-2025-52691

CVEfeed Newsroom24 mar 2026
VulnerabilitàAlta
CVE-2026-4649 - Auth bypass in Apache Artemis allows reading all internal messages

CVE ID :CVE-2026-4649 Published : March 24, 2026, 9:16 a.m. | 2 hours, 35 minutes ago Description :Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and injection of new message ( CVE-2026-27446 https://www.cve.org/CVERecord ). Since KNIME Business Hub uses Apache Artemis it is also affected by the issue. However, since Apache Artemis is not exposed to the outside it requires at least normal user privileges and the ability to execute workflows in an executor. Such a user can install and register a federated mirror without authentication to the original Apache Artemis instance and thereby read all internal messages and inject new messages. The issue affects all versions of KNIME Business Hub. A fixed version of Apache Artemis is shipped with versions 1.18.0, 1.17.4, and 1.16.3. We recommend updating to a fixed version as soon as possible since no workaround is known. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
News
Bridge or Backdoor? Critical 9.8 RCE Flaw Threatens Helmholz Industrial Networks

Bridge or Backdoor? Critical 9.8 RCE Flaw Threatens Helmholz Industrial Networks Industrial connectivity specialist Helmholz GmbH & Co. KG has issued an urgent security advisory regarding multiple vulnerabilities discovered in its myREX24V2 and myREX24V2.virtual remote access solu ... Read more Published Date: Mar 24, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32969 CVE-2026-32968 CVE-2026-3587 CVE-2025-32432 CVE-2020-10383

CVEfeed Newsroom24 mar 2026
News
Chrome Security Update Fixes 8 Vulnerabilities Allowing Remote Code Execution

Chrome Security Update Fixes 8 Vulnerabilities Allowing Remote Code Execution Google has rolled out an urgent security update for the Chrome browser to address eight high-severity vulnerabilities. These newly patched security flaws could allow threat actors to execute arbitrary ... Read more Published Date: Mar 24, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4680 CVE-2026-4679 CVE-2026-4678 CVE-2026-4677 CVE-2026-4676 CVE-2026-4675 CVE-2026-4674 CVE-2026-4673

CVEfeed Newsroom24 mar 2026
VulnerabilitàAlta
CVE-2026-3509 (CVSS 7.5)

An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.

NVD (NIST)24 mar 2026
VulnerabilitàAlta
CVE-2026-32642 - Apache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permission

CVE ID :CVE-2026-32642 Published : March 24, 2026, 8:16 a.m. | 1 hour, 36 minutes ago Description :Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized to create the corresponding address. When the OpenWire connection is closed the address is removed. This issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0. Users are recommended to upgrade to version 2.53.0, which fixes the issue. Severity: 2.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2026-3509 - CODESYS Control Audit Log Format String DoS

CVE ID :CVE-2026-3509 Published : March 24, 2026, 8:16 a.m. | 3 hours, 36 minutes ago Description :An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2025-41660 (CVSS 8.8)

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

NVD (NIST)24 mar 2026

Pagina 3177 di 3789

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.