Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

15732 risultati

News
Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database

Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database A security vulnerability was found in Dgraph, the high-performance, horizontally scalable GraphQL database. The flaw, designated as CVE-2026-33976, has been assigned a rare CVSS score of 10.0, the hig ... Read more Published Date: Apr 05, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616 CVE-2026-5281 CVE-2026-3502 CVE-2026-33032 CVE-2026-33976 CVE-2026-21962

CVEfeed Newsroom05 apr 2026
VulnerabilitàAlta
CVE-2026-5570 - Technostrobe HI-LED-WR120-G2 LoginCB index_config improper authentication

CVE ID :CVE-2026-5570 Published : April 5, 2026, 2:16 p.m. | 5 hours, 39 minutes ago Description :A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5599 - API allows deletion of users of other instance

CVE ID :CVE-2026-5599 Published : April 5, 2026, 1:17 p.m. | 6 hours, 38 minutes ago Description :A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5567 (CVSS 8.8)

A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2026-5566 (CVSS 8.8)

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBind results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2026-5566 - UTT HiPER 1250GW formNatStaticMap strcpy buffer overflow

CVE ID :CVE-2026-5566 Published : April 5, 2026, 1:17 p.m. | 6 hours, 38 minutes ago Description :A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBind results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5567 - Tenda M3 Destination setAdvPolicyData buffer overflow

CVE ID :CVE-2026-5567 Published : April 5, 2026, 1:17 p.m. | 6 hours, 38 minutes ago Description :A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5568 - Akaunting Invoice/Billing cross site scripting

CVE ID :CVE-2026-5568 Published : April 5, 2026, 1:17 p.m. | 6 hours, 38 minutes ago Description :A vulnerability has been found in Akaunting up to 3.1.21. This issue affects some unknown processing of the component Invoice/Billing. The manipulation of the argument notes leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5565 (CVSS 7.3)

A security vulnerability has been detected in code-projects Simple Laundry System 1.0. Affected by this issue is some unknown functionality of the file /delmemberinfo.php of the component Parameter Handler. Such manipulation of the argument userid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2026-5565 - code-projects Simple Laundry System Parameter delmemberinfo.php sql injection

CVE ID :CVE-2026-5565 Published : April 5, 2026, 1:17 p.m. | 6 hours, 38 minutes ago Description :A security vulnerability has been detected in code-projects Simple Laundry System 1.0. Affected by this issue is some unknown functionality of the file /delmemberinfo.php of the component Parameter Handler. Such manipulation of the argument userid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5569 - Technostrobe HI-LED-WR120-G2 Endpoint access control

CVE ID :CVE-2026-5569 Published : April 5, 2026, 2:16 p.m. | 5 hours, 39 minutes ago Description :A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been made public and could be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
News
Researchers didn’t want to glamorize cybercrims. So they roasted them

Researchers didn’t want to glamorize cybercrims. So they roasted them interview Cybercrime crews have become almost mystical entities, with security vendors assigning them names like Wizard Spider and Velvet Tempest. They hide out in hidden corners of the dark web (ofte ... Read more Published Date: Apr 05, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20045

CVEfeed Newsroom05 apr 2026

Pagina 515 di 1311

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.