Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

29111 risultati

VulnerabilitàAlta
CVE-2026-46693 - ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking

CVE ID :CVE-2026-46693 Published : June 10, 2026, 11:16 p.m. | 4 hours, 1 minute ago Description :ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in versions 6.9.13-48 and 7.1.2-23. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-46692 - ImageMagick: Heap Buffer Over-Write in distributed pixel cache server

CVE ID :CVE-2026-46692 Published : June 10, 2026, 11:16 p.m. | 4 hours, 1 minute ago Description :ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-write in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-47342 - Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass

CVE ID :CVE-2026-47342 Published : June 10, 2026, 11:16 p.m. | 6 hours, 2 minutes ago Description :A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-46645 - SQLAdmin: Authorization Bypass on `ajax_lookup`

CVE ID :CVE-2026-46645 Published : June 10, 2026, 11:16 p.m. | 2 hours, 1 minute ago Description :SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endpoints enforce. If a developer restricts model access by overriding is_accessible(), an authenticated user can still query that model's data through the ajax_lookup endpoint — silently bypassing the restriction. This issue has been patched in version 0.25.1. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-50223 - Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution

CVE ID :CVE-2026-50223 Published : June 10, 2026, 11:16 p.m. | 6 hours, 2 minutes ago Description :Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-46695 - BoxLite: Permission Bypass in boxlite Allows Modification of Read-Only Files

CVE ID :CVE-2026-46695 Published : June 10, 2026, 11:16 p.m. | 6 hours, 2 minutes ago Description :Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the directory in rw mode, thereby gaining write access to that directory. This allows malicious code to perform arbitrary write operations on directories that should be read-only. This issue has been patched in version 0.9.0. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-46703 - BoxLite: Path Traversal Vulnerability in boxlite Leads to Arbitrary File Write on the Host

CVE ID :CVE-2026-46703 Published : June 10, 2026, 11:16 p.m. | 6 hours, 2 minutes ago Description :Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not account for the possibility that entries may be symlinks pointing to absolute paths. An attacker can craft a malicious OCI image and distribute it on image hosting platforms such as DockerHub, tricking users into using it. Once a user loads the malicious image, the attacker can write arbitrary content to any path on the host, which can further lead to remote code execution on the host. This issue has been patched in version 0.9.0. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-47213 - BoxLite: Timeout Bypass Vulnerability

CVE ID :CVE-2026-47213 Published : June 10, 2026, 11:16 p.m. | 6 hours, 2 minutes ago Description :Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, Boxlite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the Boxlite service. This issue has been patched via commit 28159fc. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-53738 (CVSS 8.1)

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.

NVD (NIST)10 giu 2026
VulnerabilitàAlta
CVE-2026-53634 - Sharp: Missing Authorization Check in Quick Creation Command Endpoints

CVE ID :CVE-2026-53634 Published : June 10, 2026, 10:17 p.m. | 1 hour, 1 minute ago Description :Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enforce any authorization check. An authenticated Sharp user without create permission on a given entity could bypass the authorization layer and either retrieve the creation form or submit new records for that entity, as long as it had a Quick Creation Command handler configured. This issue has been patched in version 9.22.3. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-48011 - Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames

CVE ID :CVE-2026-48011 Published : June 10, 2026, 10:17 p.m. | 1 hour, 1 minute ago Description :Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-46673 - Russh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releases

CVE ID :CVE-2026-46673 Published : June 10, 2026, 10:17 p.m. | 1 hour, 1 minute ago Description :Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation/locking paths. In current russh releases, local SSH agent peers could still feed attacker-controlled frame lengths into buffer growth before validation. In older russh releases before 0.58.0, remote SSH traffic also reached CryptoVec through transport and compression buffers. This issue has been patched in version 0.60.3. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026

Pagina 654 di 2426

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.