Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

28482 risultati

VulnerabilitàAlta
CVE-2026-34027 - Upload restriction bypass in Wertheim SafeController Software allows authenticated users to upload arbitrary files

CVE ID :CVE-2026-34027 Published : June 15, 2026, 12:16 p.m. | 1 hour, 25 minutes ago Description :The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint. The application validates uploaded files based on the user-controlled HTTP Content-Type value and accepts the upload if this value contains an allowed string such as pdf, jpeg, tiff, or png. An authenticated attacker with any role or permission level can spoof the Content-Type value and upload arbitrary file content. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 giu 2026
VulnerabilitàAlta
CVE-2026-34026 - Path traversal in Wertheim SafeController Software allows authenticated users to download arbitrary files

CVE ID :CVE-2026-34026 Published : June 15, 2026, 12:16 p.m. | 1 hour, 25 minutes ago Description :Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path using attacker-controlled input without sufficient validation, allowing an authenticated attacker with any role or permission level to traverse out of the intended document directory and download arbitrary files accessible to the application. This includes, but is not limited to, application log files containing sensitive information and application binaries. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 giu 2026
VulnerabilitàAlta
CVE-2026-34021 - Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay

CVE ID :CVE-2026-34021 Published : June 15, 2026, 12:16 p.m. | 1 hour, 25 minutes ago Description :The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the microcontroller can sniff RS-485 messages and replay previously observed messages. This can be used, for example, to spoof a "quit alarm" message and continuously deactivate the safe alarm. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 giu 2026
VulnerabilitàAlta
CVE-2026-34023 - Broken WebSocket authorization in Wertheim SafeController Software allows cross-branch access to restricted functions

CVE ID :CVE-2026-34023 Published : June 15, 2026, 12:16 p.m. | 1 hour, 25 minutes ago Description :The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communication used by the SafeController WebMessageBroker. An authenticated attacker with valid low-privileged branch user credentials can manipulate WebSocket messages by specifying controller identifiers belonging to other branches. This allows the attacker to access restricted functions and resources in other branches, including activating boxes outside of the user's authorized branch. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 giu 2026
VulnerabilitàAlta
CVE-2026-34024 - Missing authorization checks in Wertheim SafeController Software allow low-privileged users to access restricted functions

CVE ID :CVE-2026-34024 Published : June 15, 2026, 12:16 p.m. | 1 hour, 25 minutes ago Description :The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. An authenticated attacker with minimal privileges can access endpoints that are not visible in the frontend but remain directly reachable. This allows the attacker to perform restricted actions such as switching the user's branch, uploading arbitrary files, downloading arbitrary files, and viewing details of arbitrary branches. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 giu 2026
VulnerabilitàAlta
CVE-2026-34025 - IP restriction bypass in Wertheim SafeController Software allows logins from unauthorized network locations

CVE ID :CVE-2026-34025 Published : June 15, 2026, 12:16 p.m. | 1 hour, 25 minutes ago Description :The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability in the login process. The application restricts user logins based on the IP address associated with a branch location, but the client IP address is derived from the HTTP X-Forwarded-For header when that header is present. An attacker with valid branch user credentials can manipulate the X-Forwarded-For header during login to spoof the expected branch IP address and obtain a valid authenticated session from an unauthorized network location. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 giu 2026
VulnerabilitàAlta
CVE-2026-34022 - Weak custom cryptography and hard-coded keys in Wertheim SafeController 65000 allow traffic decryption

CVE ID :CVE-2026-34022 Published : June 15, 2026, 12:16 p.m. | 1 hour, 25 minutes ago Description :The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded cryptographic keys to protect communication. An attacker in an adversary-in-the-middle position can decrypt the data traffic. During reassessment, it was possible to break the encryption/decryption routine and decrypt messages without knowledge of the encryption key. It was also possible to gain knowledge about the encryption key by intercepting enough messages. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 giu 2026
VulnerabilitàAlta
CVE-2026-12057 - DoS + Remote Code Execution via PDF JavaScript in Foxit AI

CVE ID :CVE-2026-12057 Published : June 15, 2026, 12:16 p.m. | 1 hour, 25 minutes ago Description :When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 giu 2026
News
VeraCrypt meldt probleem met plausible deniability van hidden volumes

VeraCrypt meldt probleem met plausible deniability van hidden volumes maandag 15 juni 2026, 14:15 door Redactie, 1 reactiesLaatst bijgewerkt: Vandaag, 15:40 Er is een nieuwe versie van encryptiesoftware VeraCrypt verschenen, maar dit kan voor problemen zorgen met de pla ... Read more Published Date: Jun 15, 2026 (3 days, 1 hour ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom15 giu 2026
News
Vulnerability in Responsive FileManager software

Vulnerability in Responsive FileManager software Vulnerability in Responsive FileManager software CVE ID CVE-2026-5482 Publication date 15 June 2026 Vendor Tecrail Product Responsive FileManager Vulnerable versions All through 9.14.0 Vulnerability t ... Read more Published Date: Jun 15, 2026 (2 days, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5482

CVEfeed Newsroom15 giu 2026
News
Vulnerability in Quick.CMS software

Vulnerability in Quick.CMS software Vulnerability in Quick.CMS software CVE ID CVE-2026-11860 Publication date 15 June 2026 Vendor OpenSolution Product Quick.CMS Vulnerable versions All through 6.8 until patch published on 14.05.2026 Vu ... Read more Published Date: Jun 15, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-11860

CVEfeed Newsroom15 giu 2026
VulnerabilitàAlta
CVE-2026-44188 - Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expiration

CVE ID :CVE-2026-44188 Published : June 15, 2026, 10:16 a.m. | 3 hours, 25 minutes ago Description :A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a user logs out, they can continue to authenticate and access sensitive data. This is because the application fails to invalidate the token on the backend, leaving it valid until its natural expiration. This can lead to unauthorized read access to Ansible resources such as inventories, playbooks, and configuration data. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 giu 2026

Pagina 560 di 2374

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.