Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

30472 risultati

VulnerabilitàAlta
CVE-2026-21033 - Samsung Assistant: ExpressHomeWidgetReceiver Component Export Vulnerability

CVE ID :CVE-2026-21033 Published : June 5, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàCritica
CVE-2026-6274 (CVSS 9.8)

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.

NVD (NIST)05 giu 2026
VulnerabilitàAlta
CVE-2026-11332 (CVSS 7.8)

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

NVD (NIST)05 giu 2026
VulnerabilitàAlta
CVE-2026-6274 - Authentication Bypass in DTS Electronics' Redline WR3200

CVE ID :CVE-2026-6274 Published : June 5, 2026, 9:16 a.m. | 1 hour, 16 minutes ago Description :Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-11332 - Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution

CVE ID :CVE-2026-11332 Published : June 5, 2026, 9:16 a.m. | 1 hour, 16 minutes ago Description :A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-49777 - WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability

CVE ID :CVE-2026-49777 Published : June 5, 2026, 9:16 a.m. | 1 hour, 16 minutes ago Description :Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.3. No patched version is available - the vendor has applied a fix to an existing release without publishing a new version. While the patch provided by the vendor is valid, releasing it under the existing version number leaves users unable to reliably determine whether they are running a patched or vulnerable installation. As a result, we treat this as an unpatched version. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
News
Kritieke lekken in Exchange Online en Copilot maakten datadiefstal mogelijk

Kritieke lekken in Exchange Online en Copilot maakten datadiefstal mogelijk Microsoft heeft kritieke kwetsbaarheden in Exchange Online en Copilot gepatcht die het stelen van data mogelijk maakten. Ook is een M365 Copilot-lek verholpen dat tot remote code execution (RCE) kon l ... Read more Published Date: Jun 05, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-48579 CVE-2026-47644 CVE-2026-45497 CVE-2026-42824

CVEfeed Newsroom05 giu 2026
News
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site com ... Read more Published Date: Jun 05, 2026 (3 days, 11 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-0257 CVE-2026-39987 CVE-2026-3300 CVE-2024-21182

CVEfeed Newsroom05 giu 2026
VulnerabilitàAlta
CVE-2026-48907 - Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5

CVE ID :CVE-2026-48907 Published : June 5, 2026, 8:16 a.m. | 2 hours, 16 minutes ago Description :A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-9088 - Keycloak: keycloak: information disclosure due to user profile permission bypass

CVE ID :CVE-2026-9088 Published : June 5, 2026, 8:16 a.m. | 2 hours, 16 minutes ago Description :A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
News
Cisco waarschuwt voor actief misbruikt beveiligingslek in SD-WAN Manager

Cisco waarschuwt voor actief misbruikt beveiligingslek in SD-WAN Manager Cisco waarschuwt voor een actief misbruikt beveiligingslek in Cisco Catalyst SD-WAN Manager waardoor een aanvaller met toegang tot het systeem willekeurige commando's als root kan uitvoeren. Er zijn u ... Read more Published Date: Jun 05, 2026 (3 days, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20245 CVE-2026-20182 CVE-2026-20127

CVEfeed Newsroom05 giu 2026
VulnerabilitàAlta
CVE-2026-21837 - HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API

CVE ID :CVE-2026-21837 Published : June 5, 2026, 7:16 a.m. | 3 hours, 16 minutes ago Description :HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026

Pagina 854 di 2540

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.