Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

29132 risultati

VulnerabilitàAlta
CVE-2026-40376 (CVSS 7.5)

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2026-40371 (CVSS 8.8)

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2026-34335 (CVSS 7)

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2026-33828 (CVSS 7.8)

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2026-32193 (CVSS 8.8)

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

NVD (NIST)09 giu 2026
VulnerabilitàCritica
CVE-2026-26142 (CVSS 9.8)

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

NVD (NIST)09 giu 2026
News
Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code

Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution. Tracked as CVE-2026-44963, the vulnerability carries a C ... Read more Published Date: Jun 09, 2026 (1 day, 16 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 giu 2026
VulnerabilitàCritica
CVE-2026-8025 (CVSS 9.8)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Platform: through 09062026.  NOTE: The vendor was contacted and it was learned that the product is not supported.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2026-8045 - Schneider Electric Data Center Expert XXE Information Disclosure

CVE ID :CVE-2026-8045 Published : June 9, 2026, 4:16 p.m. | 19 minutes ago Description :CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-49948 (CVSS 8.1)

Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only verifies authentication via JWT or X-API-Key without validating the caller's role. Any authenticated user holding a distributed API key can redirect all LLM and embedder traffic to an attacker-controlled server, with the malicious configuration persisted to PostgreSQL and surviving server restarts to affect all users and API keys on the instance.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2026-49938 - Fortinet FortiPortal Improper Access Control

CVE ID :CVE-2026-49938 Published : June 9, 2026, 4:16 p.m. | 19 minutes ago Description :A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-24065 - Local Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOS

CVE ID :CVE-2026-24065 Published : June 9, 2026, 4:16 p.m. | 19 minutes ago Description :Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and the time the helper performs validation, causing the helper to trust an attacker-controlled process. This allows the attacker to invoke privileged operations, resulting in arbitrary code execution as root. The issue is fixed in version 16.6.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026

Pagina 687 di 2428

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.