Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

30291 risultati

VulnerabilitàAlta
CVE-2026-11501 - SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection

CVE ID :CVE-2026-11501 Published : June 8, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=save_patient. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2026-11500 - Weaviate Static API Key client.go validateConfig authorization

CVE ID :CVE-2026-11500 Published : June 8, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. It is stated that the exploitability is difficult. The exploit is publicly available and might be used. Upgrading to version 1.38.0-rc.0 is able to resolve this issue. The identifier of the patch is 40f2cc32279f0f8a51016c3c6870a2c0c808e6c0. You should upgrade the affected component. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2024-56120 - Cisco Unified Communications Manager SQL Injection

CVE ID :CVE-2024-56120 Published : June 8, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2024-56123 - Microsoft Word XML External Entity Injection

CVE ID :CVE-2024-56123 Published : June 8, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2024-56121 - OpenSSL: Improper Certificate Validation Weakness

CVE ID :CVE-2024-56121 Published : June 8, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2024-56122 - Microsoft Exchange Server Remote Code Execution

CVE ID :CVE-2024-56122 Published : June 8, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2026-3238 (CVSS 7.5)

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.

NVD (NIST)08 giu 2026
VulnerabilitàAlta
CVE-2026-3238 - Samba: denial of service against ad dc wins server

CVE ID :CVE-2026-3238 Published : June 8, 2026, 9:16 a.m. | 3 hours, 17 minutes ago Description :A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàCritica
CVE-2026-11499 (CVSS 9.8)

A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote.

NVD (NIST)08 giu 2026
VulnerabilitàAlta
CVE-2026-11498 (CVSS 8.8)

A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely.

NVD (NIST)08 giu 2026
VulnerabilitàAlta
CVE-2026-11499 - Tenda HG7HG9/HG10 formDOMAINBLK stack-based overflow

CVE ID :CVE-2026-11499 Published : June 8, 2026, 9:16 a.m. | 1 hour, 17 minutes ago Description :A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026
VulnerabilitàAlta
CVE-2026-11498 - Tenda HG7HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow

CVE ID :CVE-2026-11498 Published : June 8, 2026, 9:16 a.m. | 1 hour, 17 minutes ago Description :A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 giu 2026

Pagina 813 di 2525

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.