Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

17434 risultati

News
Critical 9.8 CVSS RCE Vulnerabilities Exposed in Progress ShareFile

Critical 9.8 CVSS RCE Vulnerabilities Exposed in Progress ShareFile Image: watchTowr Labs A duo of severe security vulnerabilities has been uncovered in Progress ShareFile, a widely used managed file transfer solution. The flaws, discovered by the research team at wat ... Read more Published Date: Apr 03, 2026 (2 days, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-2701 CVE-2026-2699 CVE-2026-5281 CVE-2026-3502 CVE-2026-33032 CVE-2026-21962

CVEfeed Newsroom03 apr 2026
VulnerabilitàAlta
CVE-2026-5463 - Metasploit Command Injection

CVE ID :CVE-2026-5463 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended commands, potentially leading to arbitrary command execution and manipulation of Metasploit sessions. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35549 - MariaDB Server Caching Sha2 Password Authentication Plugin Crash Vulnerability

CVE ID :CVE-2026-35549 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-5454 - GRID Organiser App co.gridapp.organiser app.json hard-coded key

CVE ID :CVE-2026-5454 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file file res/raw/app.json of the component co.gridapp.organiser. Performing a manipulation of the argument SegmentWriteKey results in use of hard-coded cryptographic key . The attack is only possible with local access. The exploit has been made public and could be used. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-5453 - Rico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded key

CVE ID :CVE-2026-5453 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processing of the file br/com/rico/mobile/di/SegmentSettingsModule.java of the component br.com.rico.mobile. Such manipulation of the argument SEGMENT_WRITE_KEY leads to use of hard-coded cryptographic key . The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35542 - Roundcube Webmail Background Attribute Injection Vulnerability

CVE ID :CVE-2026-35542 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35543 - Roundcube Webmail SVG Image Injection Vulnerability

CVE ID :CVE-2026-35543 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35544 - Roundcube Webmail CSS Injection Vulnerability

CVE ID :CVE-2026-35544 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35545 - Roundcube Webmail SVG Animate Element Injection Vulnerability

CVE ID :CVE-2026-35545 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35541 - Roundcube Webmail Password Comparison Type Confusion Vulnerability

CVE ID :CVE-2026-35541 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35540 - Roundcube Webmail CSS Injection Vulnerability

CVE ID :CVE-2026-35540 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-35538 - Roundcube Webmail IMAP Injection/CSRF Bypass

CVE ID :CVE-2026-35538 Published : April 3, 2026, 5:16 a.m. | 6 hours, 38 minutes ago Description :An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026

Pagina 682 di 1453

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.