Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

30438 risultati

VulnerabilitàAlta
CVE-2026-45327 - TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection

CVE ID :CVE-2026-45327 Published : June 5, 2026, 6:17 p.m. | 15 minutes ago Description :TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version 2.5.0 fixes the issue by requiring either HTTP Basic auth or a `?password=` query parameter, comparing the supplied password against the per-mount source password (or the `default_source_password` fallback) using bcrypt, hooking into the existing brute-force IP rate-limiter (5 failed attempts per IP within 15 minutes triggers a lockout), and rejecting requests for mounts in `disabled_mounts`. The same release also tightens an adjacent endpoint, `POST /admin/golive/chunk`, which previously required session authentication but did not verify the session user's per-mount access nor check the CSRF token. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-45291 - Cloudburst Network erroneously handles invalid connections

CVE ID :CVE-2026-45291 Published : June 5, 2026, 6:17 p.m. | 15 minutes ago Description :Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a bug in Network to close the parent netty channel, rendering it inoperable. All consumers of the library should upgrade to at least version `1.0.0.CR3-20260418.124334-32`. There are no known workarounds beyond updating the library. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-45290 - Cloudburst Network has DoS in RakNet connection handling due to missing bound checks

CVE ID :CVE-2026-45290 Published : June 5, 2026, 6:17 p.m. | 15 minutes ago Description :Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a vulnerability in Network to stall the netty event loop, rendering it inoperable. All consumers of the library should upgrade to at least version `1.0.0.CR3-20260417.085727-30`. There are no known workarounds beyond updating the library. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-36500 - Controller Backup Datastore Directory Traversal

CVE ID :CVE-2026-36500 Published : June 5, 2026, 6:17 p.m. | 15 minutes ago Description :An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-36501 - Controller Externalizable DoS

CVE ID :CVE-2026-36501 Published : June 5, 2026, 6:17 p.m. | 15 minutes ago Description :An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-2379 - Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled

CVE ID :CVE-2026-2379 Published : June 5, 2026, 6:17 p.m. | 16 minutes ago Description :On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface flaps and certain agent restarts can cause IPsec tunnel re-establishment with existing Security Associations, resulting in sequence number mismatches between tunnel endpoints potentially causing unstable communication. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-11344 (CVSS 7.3)

A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form. Performing a manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used.

NVD (NIST)05 giu 2026
VulnerabilitàAlta
CVE-2026-11342 (CVSS 7.3)

A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

NVD (NIST)05 giu 2026
VulnerabilitàAlta
CVE-2026-11341 - D-Link DWR-M920 formIMEISetup sub_412DA0 os command injection

CVE ID :CVE-2026-11341 Published : June 5, 2026, 6:17 p.m. | 16 minutes ago Description :A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàCritica
CVE-2025-71318 (CVSS 9.8)

NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any credentials.

NVD (NIST)05 giu 2026
VulnerabilitàCritica
CVE-2025-71317 (CVSS 9.8)

NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which due to lax parameter validation can be shortened to /cgi-bin/login.cgi?username=eurek%20eurek) to obtain administrator privileges, allowing them to alter device configuration, enable the telnet/SSH services, and reset local user credentials.

NVD (NIST)05 giu 2026
VulnerabilitàAlta
CVE-2026-8714 - Denial-of-Service Vulnerability in RTSP Input Handling on TP-Link's Tapo C520WS

CVE ID :CVE-2026-8714 Published : June 5, 2026, 5:17 p.m. | 1 hour, 16 minutes ago Description :A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling of syntactically invalid input. Crafted inputs can trigger a processing error, causing the RTSP service to enter non-responsive state. Successful exploitation may cause the RTSP in a denial-of-service condition. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026

Pagina 844 di 2537

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.