Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32775 risultati

VulnerabilitàAlta
CVE-2025-41770 - Unauthenticated Denial of Service

CVE ID :CVE-2025-41770 Published : Aug. 12, 2026, 8:17 a.m. | 2 hours, 15 minutes ago Description :An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE9h fa
VulnerabilitàAlta
CVE-2025-41769 - Unauthenticated Buffer Overflow in PROFINET Service

CVE ID :CVE-2025-41769 Published : Aug. 12, 2026, 8:17 a.m. | 2 hours, 15 minutes ago Description :The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE9h fa
News
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other ... Read more Published Date: Aug 12, 2026 (7 hours, 19 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33634

CVEfeed Newsroom9h fa
News
Adobe dicht dozijn kritieke ColdFusion-lekken: 'Zo snel mogelijk updaten'

Adobe dicht dozijn kritieke ColdFusion-lekken: 'Zo snel mogelijk updaten' Adobe heeft een belangrijke update voor een dozijn kritieke kwetsbaarheden in ColdFusion uitgebracht en roept organisaties op om die zo snel mogelijk te installeren. Het platform is geregeld het doelw ... Read more Published Date: Aug 12, 2026 (7 hours, 26 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom9h fa
News
Cisco waarschuwt voor actief misbruik van dos-lek in vpn-service firewalls

Cisco waarschuwt voor actief misbruik van dos-lek in vpn-service firewalls Cisco waarschuwt organisaties voor actief misbruik van een kwetsbaarheid in de vpn-service van ASA- en FTD-firewalls waardoor een denial of service ontstaat. Zo kunnen aanvallers de apparaten op afsta ... Read more Published Date: Aug 12, 2026 (7 hours, 36 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-20349

CVEfeed Newsroom10h fa
News
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE iden ... Read more Published Date: Aug 12, 2026 (7 hours, 52 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom10h fa
News
Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days

Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days Microsoft’s August 2026 Patch Tuesday release addresses roughly 400 security flaws across its products, including three Zero-days. One of the three is being actively exploited, while the other two wer ... Read more Published Date: Aug 12, 2026 (8 hours, 1 minute ago) Vulnerabilities has been mentioned in this article. CVE-2026-72971 CVE-2026-68820 CVE-2026-62832 CVE-2026-6727 CVE-2026-6726 CVE-2026-56291 CVE-2026-48939 CVE-2026-50656

CVEfeed Newsroom10h fa
News
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldB ... Read more Published Date: Aug 12, 2026 (8 hours, 42 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-72971 CVE-2026-68820 CVE-2026-62832 CVE-2026-50656

CVEfeed Newsroom11h fa
VulnerabilitàAlta
CVE-2026-66659 - WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability

CVE ID :CVE-2026-66659 Published : Aug. 12, 2026, 6:22 a.m. | 4 hours, 10 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11h fa
VulnerabilitàAlta
CVE-2026-19594 - Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation

CVE ID :CVE-2026-19594 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 10 minutes ago Description :Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=` characters in query string values. An attacker with access to a downstream application built on snowflake.core could exploit the path traversal by supplying `..` as an object name, causing `snowflake.core` to issue REST requests against a parent resource or exploit the parameter pollution by injecting `&`/`#`/`=` into a free-form name field to override constraints on swap, clone, or rename operations — all executed under the application's privileged session. Successful exploitation requires the attacker to control an identifier or object-name string in an application built on snowflake.core that passes it to `snowflake.core` under a higher-privileged Snowflake session (e.g., an EXECUTE AS OWNER stored procedure, Streamlit app, or Native App). The fix is available in Snowflake Python API version 1.13.0, which also addresses several additional security findings. Users must manually upgrade. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11h fa
VulnerabilitàAlta
CVE-2026-19217 - Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget

CVE ID :CVE-2026-19217 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 11 minutes ago Description :The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11h fa
VulnerabilitàAlta
CVE-2026-19073 - Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure

CVE ID :CVE-2026-19073 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 11 minutes ago Description :The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11h fa

Pagina 6 di 2732

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.