News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
32775 risultati
CVE ID :CVE-2025-41770 Published : Aug. 12, 2026, 8:17 a.m. | 2 hours, 15 minutes ago Description :An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-41769 Published : Aug. 12, 2026, 8:17 a.m. | 2 hours, 15 minutes ago Description :The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other ... Read more Published Date: Aug 12, 2026 (7 hours, 19 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33634
Adobe dicht dozijn kritieke ColdFusion-lekken: 'Zo snel mogelijk updaten' Adobe heeft een belangrijke update voor een dozijn kritieke kwetsbaarheden in ColdFusion uitgebracht en roept organisaties op om die zo snel mogelijk te installeren. Het platform is geregeld het doelw ... Read more Published Date: Aug 12, 2026 (7 hours, 26 minutes ago) Vulnerabilities has been mentioned in this article.
Cisco waarschuwt voor actief misbruik van dos-lek in vpn-service firewalls Cisco waarschuwt organisaties voor actief misbruik van een kwetsbaarheid in de vpn-service van ASA- en FTD-firewalls waardoor een denial of service ontstaat. Zo kunnen aanvallers de apparaten op afsta ... Read more Published Date: Aug 12, 2026 (7 hours, 36 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-20349
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE iden ... Read more Published Date: Aug 12, 2026 (7 hours, 52 minutes ago) Vulnerabilities has been mentioned in this article.
Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days Microsoft’s August 2026 Patch Tuesday release addresses roughly 400 security flaws across its products, including three Zero-days. One of the three is being actively exploited, while the other two wer ... Read more Published Date: Aug 12, 2026 (8 hours, 1 minute ago) Vulnerabilities has been mentioned in this article. CVE-2026-72971 CVE-2026-68820 CVE-2026-62832 CVE-2026-6727 CVE-2026-6726 CVE-2026-56291 CVE-2026-48939 CVE-2026-50656
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldB ... Read more Published Date: Aug 12, 2026 (8 hours, 42 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-72971 CVE-2026-68820 CVE-2026-62832 CVE-2026-50656
CVE ID :CVE-2026-66659 Published : Aug. 12, 2026, 6:22 a.m. | 4 hours, 10 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19594 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 10 minutes ago Description :Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=` characters in query string values. An attacker with access to a downstream application built on snowflake.core could exploit the path traversal by supplying `..` as an object name, causing `snowflake.core` to issue REST requests against a parent resource or exploit the parameter pollution by injecting `&`/`#`/`=` into a free-form name field to override constraints on swap, clone, or rename operations — all executed under the application's privileged session. Successful exploitation requires the attacker to control an identifier or object-name string in an application built on snowflake.core that passes it to `snowflake.core` under a higher-privileged Snowflake session (e.g., an EXECUTE AS OWNER stored procedure, Streamlit app, or Native App). The fix is available in Snowflake Python API version 1.13.0, which also addresses several additional security findings. Users must manually upgrade. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19217 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 11 minutes ago Description :The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19073 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 11 minutes ago Description :The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 6 di 2732