News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
30646 risultati
CVE ID :CVE-2026-49191 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49202 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49192 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49204 Published : June 4, 2026, 7:16 a.m. | 3 hours, 16 minutes ago Description :Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49190 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-50219 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49189 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49187 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49188 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-10805 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48681 Published : June 4, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49186 Published : June 4, 2026, 4:17 a.m. | 4 hours, 15 minutes ago Description :The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 887 di 2554