Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

46396 risultati

VulnerabilitàAlta
CVE-2019-25633 - AIDA64 Extreme 5.99.4900 SEH Buffer Overflow via EggHunter

CVE ID :CVE-2019-25633 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :AIDA64 Extreme 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input through the email preferences and report wizard interfaces. Attackers can inject crafted payloads into the Display name field and Load from file parameter to trigger the overflow and execute shellcode with application privileges. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2019-25634 - Base64 Decoder 1.1.2 Local Buffer Overflow SEH Egghunter

CVE ID :CVE-2019-25634 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :Base64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input file that overflows a buffer, overwrites the SEH chain with a POP-POP-RET gadget address, and uses an egghunter payload to locate and execute shellcode for code execution. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2019-25632 - phpFileManager 1.7.8 Local File Inclusion via index.php

CVE ID :CVE-2019-25632 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2019-25631 - AIDA64 Business 5.99.4900 SEH Buffer Overflow via EggHunter

CVE ID :CVE-2019-25631 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :AIDA64 Business 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH pointers with malicious shellcode. Attackers can inject egg hunter shellcode through the SMTP display name field in preferences or report wizard functionality to trigger the overflow and execute code with application privileges. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2019-25630 - PhreeBooks ERP 5.2.3 Arbitrary File Upload via Image Manager

CVE ID :CVE-2019-25630 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2019-25628 - Download Accelerator Plus DAP 10.0.6.0 SEH Buffer Overflow

CVE ID :CVE-2019-25628 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded shellcode when imported through the application's web page import functionality. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2019-25629 - AIDA64 Extreme 5.99.4900 SEH Buffer Overflow via Logging

CVE ID :CVE-2019-25629 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :AIDA64 Extreme 5.99.4900 contains a structured exception handler buffer overflow vulnerability in the logging functionality that allows local attackers to execute arbitrary code by supplying a malicious CSV log file path. Attackers can inject shellcode through the Hardware Monitoring logging preferences to overflow the buffer and trigger code execution when the application processes the log file path. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2019-25627 - FlexHEX 2.71 Local Buffer Overflow via SEH Unicode

CVE ID :CVE-2019-25627 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2019-25626 - River Past Cam Do 3.7.6 Local Buffer Overflow in Activation Code

CVE ID :CVE-2019-25626 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbitrary code by supplying a malicious activation code string. Attackers can craft a buffer containing 608 bytes of junk data followed by shellcode and SEH chain overwrite values to trigger code execution when the activation dialog processes the input. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
VulnerabilitàAlta
CVE-2025-64998 - Session hijacking via exposed session signing secret in distributed Checkmk setups

CVE ID :CVE-2025-64998 Published : March 24, 2026, 11:25 a.m. | 26 minutes ago Description :Exposure of session signing secret in Checkmk Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026
News
Checkmarx Alert: Malicious Plugins and GitHub Actions Hit OpenVSX in New Supply Chain Attack

Checkmarx Alert: Malicious Plugins and GitHub Actions Hit OpenVSX in New Supply Chain Attack Today, security firm Checkmarx has identified a recent supply chain security incident. The breach involved the publication of malicious versions of two popular security plugins to the OpenVSX registry ... Read more Published Date: Mar 24, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-21509 CVE-2025-32432

CVEfeed Newsroom24 mar 2026
News
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials

TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials Two more GitHub Actions workflows have become the latest to be compromised by credential-stealing malware by a threat actor known as TeamPCP, the cloud-native cybercriminal operation also behind the T ... Read more Published Date: Mar 24, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33634

CVEfeed Newsroom24 mar 2026

Pagina 3254 di 3867

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.