Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32808 risultati

VulnerabilitàAlta
CVE-2026-67282 - Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8

CVE ID :CVE-2026-67282 Published : Aug. 12, 2026, 9:17 a.m. | 1 hour, 15 minutes ago Description :Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10h fa
VulnerabilitàAlta
CVE-2026-19566 - Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths

CVE ID :CVE-2026-19566 Published : Aug. 12, 2026, 9:17 a.m. | 1 hour, 15 minutes ago Description :Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to _width2bits(), which builds the mask as `'1' x ($width + 8)`, one character per bit. The _inc() method then unpacks the packed mask into a Perl array of one scalar per byte, so the prefix length alone sets the allocation size: `::/100000000` builds a 100 MB string and a 12.5 million element array. The value being tested is parsed, not just the configured ranges: contains() builds a set from its argument, and _guess_coder() tries the IPv4 coder and then the IPv6 coder, so an IPv4-only set expands an oversized IPv6 prefix length before the mixed address width check rejects it. Any caller that passes untrusted input to contains() or add() can exhaust process memory. A prefix length above 128 is also stored as a range that does not match the requested block: 2001:db8::/129 stringifies back unchanged, contains() of its own base address returns false, and removing it from a set drops the base address while the set still prints as covering it. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10h fa
News
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-5931 ... Read more Published Date: Aug 12, 2026 (8 hours, 22 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-59310 CVE-2026-59309

CVEfeed Newsroom10h fa
News
Microsoft Patchdinsdag: Misbruikt Windows-lek, kritieke updates Office en Exchange

Microsoft Patchdinsdag: Misbruikt Windows-lek, kritieke updates Office en Exchange Tijdens de patchdinsdag van augustus heeft Microsoft updates voor honderden kwetsbaarheden uitgebracht, waaronder voor een actief aangevallen Windows-lek, kritieke kwetsbaarheden in Microsoft Office d ... Read more Published Date: Aug 12, 2026 (8 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-68820 CVE-2026-65665 CVE-2026-62911 CVE-2026-62878 CVE-2026-59124

CVEfeed Newsroom10h fa
VulnerabilitàAlta
CVE-2026-19426 (CVSS 8.2)

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

NVD (NIST)11h fa
VulnerabilitàAlta
CVE-2026-19426 - FitSoft|POS Sytstem - Missing Authentication

CVE ID :CVE-2026-19426 Published : Aug. 12, 2026, 8:17 a.m. | 2 hours, 15 minutes ago Description :POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11h fa
VulnerabilitàAlta
CVE-2025-41771 - SQL injection

CVE ID :CVE-2025-41771 Published : Aug. 12, 2026, 8:17 a.m. | 2 hours, 15 minutes ago Description :An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11h fa
VulnerabilitàAlta
CVE-2025-41770 (CVSS 7.5)

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

NVD (NIST)11h fa
VulnerabilitàCritica
CVE-2025-41769 (CVSS 9.8)

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

NVD (NIST)11h fa
VulnerabilitàAlta
CVE-2025-41770 - Unauthenticated Denial of Service

CVE ID :CVE-2025-41770 Published : Aug. 12, 2026, 8:17 a.m. | 2 hours, 15 minutes ago Description :An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11h fa
VulnerabilitàAlta
CVE-2025-41769 - Unauthenticated Buffer Overflow in PROFINET Service

CVE ID :CVE-2025-41769 Published : Aug. 12, 2026, 8:17 a.m. | 2 hours, 15 minutes ago Description :The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE11h fa
News
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other ... Read more Published Date: Aug 12, 2026 (9 hours, 19 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33634

CVEfeed Newsroom11h fa

Pagina 8 di 2734

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.