Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

18203 risultati

VulnerabilitàAlta
CVE-2026-4997 - Sinaptik AI PandasAI sql_sanitizer.py is_sql_query_safe path traversal

CVE ID :CVE-2026-4997 Published : March 28, 2026, 1:16 p.m. | 12 hours, 37 minutes ago Description :A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql_sanitizer.py. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2026-4998 - Sinaptik AI PandasAI Chat Message code_executor.py CodeExecutor.execute code injection

CVE ID :CVE-2026-4998 Published : March 28, 2026, 2:15 p.m. | 13 hours, 37 minutes ago Description :A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2026-4996 (CVSS 7.3)

A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_lancedb/lancedb.py of the component pandasai-lancedb Extension. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)28 mar 2026
VulnerabilitàAlta
CVE-2018-25225 (CVSS 8.4)

SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets.

NVD (NIST)28 mar 2026
VulnerabilitàAlta
CVE-2018-25224 (CVSS 8.4)

PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets.

NVD (NIST)28 mar 2026
VulnerabilitàCritica
CVE-2018-25223 (CVSS 9.8)

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

NVD (NIST)28 mar 2026
VulnerabilitàAlta
CVE-2018-25225 - SIPP 3.3 Stack-Based Buffer Overflow via Configuration File

CVE ID :CVE-2018-25225 Published : March 28, 2026, 12:16 p.m. | 11 hours, 37 minutes ago Description :SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2018-25224 - PMS 0.42 Stack-Based Buffer Overflow via Configuration File

CVE ID :CVE-2018-25224 Published : March 28, 2026, 12:16 p.m. | 11 hours, 37 minutes ago Description :PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2018-25223 - Crashmail 1.6 Stack-based Buffer Overflow Remote Code Execution

CVE ID :CVE-2018-25223 Published : March 28, 2026, 12:16 p.m. | 11 hours, 37 minutes ago Description :Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2018-25222 (CVSS 8.4)

SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 1052 bytes to overwrite the instruction pointer and execute shellcode in the application context.

NVD (NIST)28 mar 2026
VulnerabilitàCritica
CVE-2018-25221 (CVSS 9.8)

EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.

NVD (NIST)28 mar 2026
VulnerabilitàCritica
CVE-2018-25220 (CVSS 9.8)

Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the application. Attackers can craft a malicious payload with 1200 bytes of padding followed by a return-oriented programming chain to overwrite the instruction pointer and execute shell commands with application privileges.

NVD (NIST)28 mar 2026

Pagina 829 di 1517

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.