Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

29390 risultati

VulnerabilitàAlta
CVE-2026-11680 - Google Chrome Use-After-Free in Media

CVE ID :CVE-2026-11680 Published : June 9, 2026, 12:16 a.m. | 17 minutes ago Description :Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-11679 - Google Chrome Use-After-Free Codec Sandbox Escape

CVE ID :CVE-2026-11679 Published : June 9, 2026, 12:16 a.m. | 17 minutes ago Description :Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-11678 - libyuv Integer Overflow Information Disclosure

CVE ID :CVE-2026-11678 Published : June 9, 2026, 12:16 a.m. | 17 minutes ago Description :Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-11677 - Google Chrome Sandbox Escape via Network Race Condition

CVE ID :CVE-2026-11677 Published : June 9, 2026, 12:16 a.m. | 17 minutes ago Description :Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-40215 - OpenVPN Use-After-Free Race Condition

CVE ID :CVE-2026-40215 Published : June 8, 2026, 9:16 p.m. | 1 hour, 17 minutes ago Description :A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2026-44541 - Fides: DOM-based XSS vulnerability in fides.js via fides_description override

CVE ID :CVE-2026-44541 Published : June 8, 2026, 9:16 p.m. | 1 hour, 17 minutes ago Description :Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2026-11585 - CodeAstro Student Attendance Management System createClassArms.php sql injection

CVE ID :CVE-2026-11585 Published : June 8, 2026, 9:16 p.m. | 1 hour, 18 minutes ago Description :A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
News
One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public

One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to root and break out of a container. The flaw, CVE-2026 ... Read more Published Date: Jun 08, 2026 (1 day, 15 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-0257 CVE-2026-39987 CVE-2026-23111 CVE-2024-21182

CVEfeed Newsroom08 giu 2026
VulnerabilitàAlta
CVE-2026-49141 (CVSS 7.1)

WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.

NVD (NIST)08 giu 2026
VulnerabilitàAlta
CVE-2026-49141 - WACRM Authorization Bypass via Automation Engine Endpoint

CVE ID :CVE-2026-49141 Published : June 8, 2026, 8:17 p.m. | 2 hours, 17 minutes ago Description :WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2026-47345 - TYPO3 HTML Sanitizer allows Cross-Site Scripting

CVE ID :CVE-2026-47345 Published : June 8, 2026, 8:17 p.m. | 2 hours, 17 minutes ago Description :Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2026-47344 - TYPO3 HTML Sanitizer allows Cross-Site Scripting

CVE ID :CVE-2026-47344 Published : June 8, 2026, 8:17 p.m. | 2 hours, 17 minutes ago Description :When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., ) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2. Severity: 2.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026

Pagina 726 di 2450

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.