Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

18050 risultati

VulnerabilitàAlta
CVE-2026-2285 - CVE-2026-2285

CVE ID :CVE-2026-2285 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-2286 - CVE-2026-2286

CVE ID :CVE-2026-2286 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-2287 - CVE-2026-2287

CVE ID :CVE-2026-2287 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
News
High-Severity RCE Discovered in Foreman’s WebSocket Proxy

High-Severity RCE Discovered in Foreman’s WebSocket Proxy Security researchers have identified a high-severity vulnerability in Foreman, the popular open-source lifecycle management tool used by system administrators to provision and orchestrate thousands of ... Read more Published Date: Mar 30, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-1961 CVE-2026-27728

CVEfeed Newsroom30 mar 2026
VulnerabilitàAlta
CVE-2026-5165 - Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset

CVE ID :CVE-2026-5165 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-free vulnerability. This issue could allow a local attacker to corrupt system memory, potentially leading to system instability or unexpected behavior. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-5164 - Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request

CVE ID :CVE-2026-5164 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial of Service (DoS). Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-5122 - osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control

CVE ID :CVE-2026-5122 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP OPEN Message Handler. Performing a manipulation of the argument domainNameLen results in improper access controls. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The patch is named 2b09db390a3d455808363c53e409afe6b1b86d2d. It is suggested to install a patch to address this issue. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-33373 - Zimbra Collaboration CSRF Token Vulnerability

CVE ID :CVE-2026-33373 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state transitions. Specifically, tokens generated after operations such as enabling two-factor authentication or changing a password may lack CSRF enforcement. While such a token is active, authenticated SOAP requests that trigger token generation or state changes can be performed without CSRF validation. An attacker could exploit this by inducing a victim to submit crafted requests, potentially allowing sensitive account actions such as disabling two-factor authentication. The issue is mitigated by ensuring CSRF protection is consistently enforced for all issued authentication tokens. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-30564 - SourceCodester Sales and Inventory System Reflected Cross-Site Scripting (XSS)

CVE ID :CVE-2026-30564 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-30565 - SourceCodester Sales and Inventory System Reflected Cross-Site Scripting (XSS)

CVE ID :CVE-2026-30565 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_supplier.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-30566 - SourceCodester Sales and Inventory System Reflected Cross-Site Scripting (XSS)

CVE ID :CVE-2026-30566 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_customers.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-30082 - IngEstate Server Stored XSS Vulnerability

CVE ID :CVE-2026-30082 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026

Pagina 801 di 1505

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.