Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

30519 risultati

VulnerabilitàAlta
CVE-2026-10804 - Streamlit Palette hashing.py weak hash

CVE ID :CVE-2026-10804 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Severity: 3.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-52606 - HCL iControl was affected by Weak Input Validation vulnerability. .

CVE ID :CVE-2025-52606 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-52609 - HCL iControl was affected by Missing Security Headers vulnerability.

CVE ID :CVE-2025-52609 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-12694 - Local Privilege Escalation in VPN Client

CVE ID :CVE-2025-12694 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-52608 - HCL iControl was affected by Missing Cookie Attributes vulnerability.

CVE ID :CVE-2025-52608 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
News
Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP c ... Read more Published Date: Jun 04, 2026 (3 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-3300

CVEfeed Newsroom04 giu 2026
News
Privacy-OS Tails komt wegens ernstig Linux-lek met noodpatch

Privacy-OS Tails komt wegens ernstig Linux-lek met noodpatch Het op privacy gerichte besturingssysteem Tails heeft wegens een ernstige kwetsbaarheid in de Linux-kernel een noodpatch uitgebracht. Via het beveiligingslek zou een met Tails meegeleverde applicatie ... Read more Published Date: Jun 04, 2026 (3 days, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-43503

CVEfeed Newsroom04 giu 2026
VulnerabilitàAlta
CVE-2026-49077 - WordPress WP eMember plugin <= v10.2.2 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-49077 Published : June 4, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-10801 - modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash

CVE ID :CVE-2026-10801 Published : June 4, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache Key Handler. The manipulation leads to use of weak hash. An attack has to be approached locally. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. Severity: 3.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-8916 - Samsung Open Source rlottie Out-of-Bounds Write

CVE ID :CVE-2026-8916 Published : June 4, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-50224 - Unauthenticated IPv6 WAN Management Exposure

CVE ID :CVE-2026-50224 Published : June 4, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-50226 - Firmware Theft & IMEI Spoofing via Connect-OTA

CVE ID :CVE-2026-50226 Published : June 4, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026

Pagina 873 di 2544

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.