Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

30583 risultati

VulnerabilitàAlta
CVE-2026-49193 - Publicly Readable AWS S3 Telemetry Buckets

CVE ID :CVE-2026-49193 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-49190 - Missing Per-Instruction Authorization Checks

CVE ID :CVE-2026-49190 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-50219 - Expat Use-After-Free Vulnerability

CVE ID :CVE-2026-50219 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-49189 - Broadcast Receiver Privilege Escalation

CVE ID :CVE-2026-49189 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-49187 - Hard-coded APK Resource Credentials & Scepters

CVE ID :CVE-2026-49187 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-49188 - Elevated Root Command Execution via ai_cmd Sockets

CVE ID :CVE-2026-49188 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-10805 - Networkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backend

CVE ID :CVE-2026-10805 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-48681 - OpenStack Ironic Directory Traversal File Overwrite

CVE ID :CVE-2026-48681 Published : June 4, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-49186 - Lack of MQTT Broker Topic Access Control Lists

CVE ID :CVE-2026-49186 Published : June 4, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-49185 - Instruction Injection via FieldX MDM

CVE ID :CVE-2026-49185 Published : June 4, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-44917 - OpenStack Ironic Local File Read via PXE Template

CVE ID :CVE-2026-44917 Published : June 4, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template. Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-41283 - OpenStack Mistral Arbitrary Remote Code Execution

CVE ID :CVE-2026-41283 Published : June 4, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026

Pagina 882 di 2549

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.