Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

29347 risultati

VulnerabilitàAlta
CVE-2026-44743 - Security Misconfiguration vulnerability in SAP Business Objects

CVE ID :CVE-2026-44743 Published : June 9, 2026, 1:16 a.m. | 3 hours, 18 minutes ago Description :Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information .This has a low impact on the confidentiality of the data. There is no impact on integrity and availability of the application. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-44748 - XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform

CVE ID :CVE-2026-44748 Published : June 9, 2026, 1:16 a.m. | 3 hours, 18 minutes ago Description :SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage. This causes a high impact on confidentiality, integrity and availability of the application. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-44744 - SQL Injection vulnerability in SAP S/4HANA

CVE ID :CVE-2026-44744 Published : June 9, 2026, 1:16 a.m. | 3 hours, 18 minutes ago Description :SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database queries.This flaw exposes sensitive information to which they should not otherwise have access to. The vulnerability has a high impact on the confidentiality of the data with no impact on the integrity and availability of the application. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-44746 - Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java Component UDI

CVE ID :CVE-2026-44746 Published : June 9, 2026, 1:16 a.m. | 3 hours, 18 minutes ago Description :Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL that embeds a malicious script. If a victim clicks this link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim's browser. This could allow the attacker to access and/or modify information related to the webclient, impacting the confidentiality and integrity of the application, with no impact to availability. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-40128 - Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)

CVE ID :CVE-2026-40128 Published : June 9, 2026, 1:16 a.m. | 3 hours, 18 minutes ago Description :SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable. Severity: 9.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàCritica
CVE-2026-27671 (CVSS 9.8)

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2026-24315 - Path Traversal Vulnerability in SAP Fiori (launchpad)

CVE ID :CVE-2026-24315 Published : June 9, 2026, 1:16 a.m. | 3 hours, 18 minutes ago Description :SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-27671 - Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform

CVE ID :CVE-2026-27671 Published : June 9, 2026, 1:16 a.m. | 3 hours, 18 minutes ago Description :Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-11700 - Google Chrome Use After Free

CVE ID :CVE-2026-11700 Published : June 9, 2026, 12:16 a.m. | 4 hours, 18 minutes ago Description :Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-11701 - Google Chrome Guest View UI Spoofing

CVE ID :CVE-2026-11701 Published : June 9, 2026, 12:16 a.m. | 4 hours, 18 minutes ago Description :Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-11697 - Google Chrome Sandbox Escape

CVE ID :CVE-2026-11697 Published : June 9, 2026, 12:16 a.m. | 4 hours, 18 minutes ago Description :Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-11698 - Google Chrome Use-After-Free Bluetooth Vulnerability

CVE ID :CVE-2026-11698 Published : June 9, 2026, 12:16 a.m. | 4 hours, 18 minutes ago Description :Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026

Pagina 720 di 2446

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.