News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
30179 risultati
CVE ID :CVE-2026-43974 Published : June 8, 2026, 2:12 p.m. | 21 minutes ago Description :Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the client into raw protocol mode via an unsolicited 101 Switching Protocols response. In gun_http:handle_inform/8, when a 101 Switching Protocols response is received over HTTP/1.1, the function verifies only that the Upgrade header is syntactically valid and that the stream reference is a plain reference(). It does not check whether the client ever sent an Upgrade or Connection: upgrade header on the corresponding request. Because this check is absent, any 101 response (solicited or not) causes gun to dispatch a gun_upgrade message to the caller and transition the entire connection to raw protocol mode. A malicious or compromised HTTP server can send an unsolicited 101 response to any HTTP/1.1 request, causing the gun client to abandon HTTP framing for that connection. Once in raw mode, gun_raw applies no flow control (flow=infinity) and re-arms socket active mode after every received packet, so the server can flood the client with arbitrary bytes. These are forwarded as unbounded gun_data messages to the owner process, exhausting its mailbox and BEAM memory, ultimately crashing the VM. This issue affects gun: from 2.0.0 before 2.4.0. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-28318 — SolarWinds Serv-U DoS added to CISA KEV June 8, 2026CVE: CVE-2026-28318CVSS Score: 7.5 (High)CWE: CWE-400 — Uncontrolled Resource ConsumptionKEV Added: June 5, 2026FCEB Remediation Deadline: June 19, 2026Vulnerability OverviewThe vulnerabil ... Read more Published Date: Jun 08, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20245 CVE-2026-28318
CVE ID :CVE-2026-25558 Published : June 8, 2026, 2:01 p.m. | 32 minutes ago Description :QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11520 Published : June 8, 2026, 2 p.m. | 33 minutes ago Description :A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Multiple parameters might be affected. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Check Point meldt actief misbruik van kritiek lek in Remote Access VPN Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in Check Point Remote Access VPN, waardoor een ongeauthenticeerde aanvaller zonder geldig wachtwoord een vpn-verbinding kan opzetten, zo ... Read more Published Date: Jun 08, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-50752
CVE ID :CVE-2026-11519 Published : June 8, 2026, 1:45 p.m. | 48 minutes ago Description :A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the component Account Creation Handler. The manipulation of the argument ROLE results in improper authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11518 Published : June 8, 2026, 1:30 p.m. | 1 hour, 3 minutes ago Description :A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The manipulation of the argument fullname/username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked. A chatbot g ... Read more Published Date: Jun 08, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-9549 Published : June 8, 2026, 1:16 p.m. | 1 hour, 17 minutes ago Description :Stored cross-site scripting in the service discovery active check output in Checkmk Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7765 Published : June 8, 2026, 1:16 p.m. | 1 hour, 17 minutes ago Description :Incorrect authorization in the User Messages dashboard widget in Checkmk Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7186 Published : June 8, 2026, 1:16 p.m. | 1 hour, 17 minutes ago Description :Stored cross-site scripting in the URL dashboard widget in Checkmk Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8078 Published : June 8, 2026, 1:16 p.m. | 1 hour, 17 minutes ago Description :Stored cross-site scripting in the global settings change log in Checkmk Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 800 di 2515