Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

47266 risultati

VulnerabilitàAlta
CVE-2026-91864 - Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion

CVE ID :CVE-2026-91864 Published : Sept. 21, 2026, 11:26 a.m. | 1 hour, 1 minute ago Description :A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-91863 - Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service

CVE ID :CVE-2026-91863 Published : Sept. 21, 2026, 11:25 a.m. | 1 hour, 2 minutes ago Description :A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-16652 - Temporal Server Schedule exclusion search can cause excessive CPU consumption

CVE ID :CVE-2026-16652 Published : Sept. 21, 2026, 11:23 a.m. | 1 hour, 3 minutes ago Description :Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that combines a fine-grained cadence with an exclusion calendar that rejects every candidate time, causing the server to evaluate excluded candidates without a per-search work budget. This can consume excessive CPU in Frontend and Schedule worker components. A persisted specification can also cause its backing Schedule Workflow to repeatedly fail and retry, allowing CPU consumption to continue without additional requests until the Schedule is deleted or its backing Workflow is terminated. Repeated or parallel exploitation can deny service. The issue affects availability only; it does not expose or modify Workflow data. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-77021 - Missing decompression size limit in agent receiver allows memory exhaustion via push agent data

CVE ID :CVE-2026-77021 Published : Sept. 21, 2026, 11:17 a.m. | 1 hour, 10 minutes ago Description :Improper handling of highly compressed data (data amplification) in Checkmk Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-92612 - Eclipse iceoryx2 StaticString Memory Safety Vulnerability

CVE ID :CVE-2026-92612 Published : Sept. 21, 2026, 11:17 a.m. | 1 hour, 10 minutes ago Description :In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust. Severity: 1.0 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-92574 (CVSS 8.8)

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-92574 - Cri-o: cri-o checkpoint restore bypasses destination security context

CVE ID :CVE-2026-92574 Published : Sept. 21, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-91921 - Cross-Site Scripting (XSS) in 1millionbot’s AI chatbot platform

CVE ID :CVE-2026-91921 Published : Sept. 21, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the web interface by sending messages containing Markdown syntax and certain unsanitised content blocks. The impact is limited to the user’s own interactive session; no compromise of internal infrastructure, access to third-party data or impact on administrative panels has been identified. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94277 - Stored Cross-Site Scripting in MISP Galaxy Matrix Statistics via Unescaped Galaxy Name

CVE ID :CVE-2026-94277 Published : Sept. 21, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the perm_galaxy_editor permission can create or modify a galaxy whose name contains arbitrary HTML or JavaScript markup. Because the value is interpolated verbatim into the page, any user who subsequently opens the galaxy matrix statistics page will have the embedded script executed in their browser context. This enables session hijacking, credential theft, data exfiltration, or the performance of arbitrary actions on behalf of the victim within the MISP application. Version affected: Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-92400 - Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion

CVE ID :CVE-2026-92400 Published : Sept. 21, 2026, 9:17 a.m. | 3 hours, 10 minutes ago Description :The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own orders as paid using a genuine transaction from a payment sandbox they control. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94152 - Omega Solution FBP Fulfillment by People User Profile API user authorization

CVE ID :CVE-2026-94152 Published : Sept. 21, 2026, 9:17 a.m. | 3 hours, 10 minutes ago Description :A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94150 - Omega Solution HRM OS SVG File Upload view cross site scripting

CVE ID :CVE-2026-94150 Published : Sept. 21, 2026, 9:17 a.m. | 3 hours, 10 minutes ago Description :A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026

Pagina 414 di 3939

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.