News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
30583 risultati
Cisco Unified Communications Manager Vulnerability Exposed Along With PoC Exploit Code Cisco has disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Tracked as CVE-2026- ... Read more Published Date: Jun 04, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20230
CISA Warns of Android Framework Integer Overflow Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly identified Android Framework vulnerability, tracked as CVE-2025-48595, to its Known Exploited Vulnerabilities (KEV) c ... Read more Published Date: Jun 04, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-48595
Magento-webwinkels aangevallen via kritieke Mirasvit-kwetsbaarheid Op Magento gebaseerde webwinkels worden aangevallen via een kritieke kwetsbaarheid in Mirasvit Full Page Cache Warmer. Via het beveiligingslek kan een ongeauthenticeerde aanvaller willekeurige code op ... Read more Published Date: Jun 04, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45247
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited ... Read more Published Date: Jun 04, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45247 CVE-2026-45659 CVE-2026-0257 CVE-2026-39987 CVE-2024-21182
CVE ID :CVE-2026-50205 Published : June 4, 2026, 7:16 a.m. | 3 hours, 16 minutes ago Description :System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-50206 Published : June 4, 2026, 7:16 a.m. | 3 hours, 16 minutes ago Description :Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49193 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49202 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49203 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49191 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49194 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49204 Published : June 4, 2026, 7:16 a.m. | 3 hours, 16 minutes ago Description :Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 881 di 2549