News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
29137 risultati
CVE ID :CVE-2026-41974 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 3.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41973 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41977 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41976 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Severity: 6.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41972 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-62858 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Google komt met update voor actief aangevallen kwetsbaarheid in Chrome Google heeft een beveiligingsupdate uitgebracht voor een actief aangevallen kwetsbaarheid in Chrome. Daarnaast zijn meerdere beveiligingslekken verholpen die als kritiek zijn aangemerkt. Het aangevall ... Read more Published Date: Jun 09, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-11645
LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of ... Read more Published Date: Jun 09, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-48710 CVE-2026-45659 CVE-2026-0257 CVE-2026-42271 CVE-2026-42208 CVE-2026-39987 CVE-2024-21182
CVE ID :CVE-2026-8981 Published : June 9, 2026, 6:16 a.m. | 2 hours, 18 minutes ago Description :The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary JavaScript that executes for any visitor of pages embedding the affected block. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-5067 Published : June 9, 2026, 6:16 a.m. | 2 hours, 18 minutes ago Description :A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a bounded copy that does not guarantee NUL termination when the input length reaches the buffer size. During upgrade handling the buffer is copied to a local stack buffer and passed to strlen(); if no NUL exists in-bounds, strlen() reads beyond the stack buffer and subsequent concatenation with the WebSocket magic string can write out of bounds. This leads to out-of-bounds read and write on stack memory, resulting in crash (denial of service) and potentially code execution. The path is reachable when CONFIG_HTTP_SERVER_WEBSOCKET is enabled. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4986 Published : June 9, 2026, 6:16 a.m. | 2 hours, 18 minutes ago Description :The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11572 Published : June 9, 2026, 6:16 a.m. | 2 hours, 18 minutes ago Description :Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exec() method by _cloneWithGit() and fetchRefs() functions. An attacker can execute arbitrary operating system commands as the process user by supplying a specially crafted git repository name. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 698 di 2429