News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
46998 risultati
CVE ID :CVE-2026-63274 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In fixed versions the declared length is clamped to the bytes actually read. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-63273 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer wrote past its end. In fixed versions a declared key length larger than the buffer is rejected. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-63272 Published : Sept. 22, 2026, 11:10 a.m. | 1 hour, 17 minutes ago Description :LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the array was the shorter of the two. In fixed versions an advance array shorter than its text is ignored. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Slechts één van 225 aan Anthropic gelinkte kwetsbaarheden actief misbruikt Van de 225 kwetsbaarheden die zijn ontdekt door onderzoekers van Anthropic en deelnemers aan Project Glasswing, wordt voor zover bekend slechts één actief misbruikt. Dat stelt beveiligingsonderzoeker ... Read more Published Date: Sep 22, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-26980
CVE ID :CVE-2026-25265 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Privilege escalation due to weak configuration while temporary file handling. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-25264 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Privilege escalation due to weak configuration during package extraction process. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-25262 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Memory corruption while processing a crafted ELF file in the Primary Bootloader. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-25255 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Exposed dangerous function lead to privilege escalation via gRPC server. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-25254 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Improper authorization leads to Remote Code Execution via SocketIO interface. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-90882 Published : Sept. 22, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to the service in a logged-in user's browser and read the responses. This exposed /user (login name, avatar, homepage, tokens URL), /user/tokens, /user/namespaces, /user/extensions, /user/search/{name} and /user/namespace/{name}/members, and — because /user/csrf was readable the same way — allowed the CSRF protection on write endpoints to be defeated. Chaining the two, an attacker page could call /user/token/create and exfiltrate a personal access token carrying publish and delete rights over the victim's namespaces. The headers were emitted by the CDN/edge layer, not by the application: the Open VSX software sets allowCredentials(true) in exactly one place, against a single exact origin derived from ovsx.webui.url, and defines no CORS mapping on /user/ beyond it. No configuration of the software produces origin reflection with credentials. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
A privilege escalation vulnerability was found in CUPS when used with the cups-filters serial backend. A local user who is a member of the lpadmin group can configure a printer that uses a privileged serial backend. The CUPS scheduler does not restrict the path component of non-file device URIs, so the root-privileged backend can write attacker-controlled print data to an arbitrary file. This can be used to change security-sensitive CUPS configuration and ultimately achieve root code execution. Exploitation requires local lpadmin group membership and a serial backend binary installed with root-only permissions.
Pagina 372 di 3917