Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

30894 risultati

VulnerabilitàAlta
CVE-2026-10729 - HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens

CVE ID :CVE-2026-10729 Published : June 3, 2026, 2:16 p.m. | 2 hours, 16 minutes ago Description :An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df. Severity: 1.2 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2025-70101 - lwext4 Out-of-Bounds Read

CVE ID :CVE-2025-70101 Published : June 3, 2026, 2:16 p.m. | 2 hours, 16 minutes ago Description :An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before performing a binary search over extent index entries, which can result in invalid pointer calculations and an out-of-bounds memory read during extent tree traversal. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2025-70100 - lwext4 Divide By Zero

CVE ID :CVE-2025-70100 Published : June 3, 2026, 2:16 p.m. | 16 minutes ago Description :A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2025-60477 - GPAC MP4Box NULL Pointer Dereference Denial of Service

CVE ID :CVE-2025-60477 Published : June 3, 2026, 2:16 p.m. | 16 minutes ago Description :A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2024-47263 - Synology Hyper Backup Path Traversal

CVE ID :CVE-2024-47263 Published : June 3, 2026, 2:16 p.m. | 16 minutes ago Description :An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2024-47273 - Synology Hyper Backup Path Traversal

CVE ID :CVE-2024-47273 Published : June 3, 2026, 2:16 p.m. | 16 minutes ago Description :An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2022-49042 (CVSS 7.8)

An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.

NVD (NIST)03 giu 2026
VulnerabilitàAlta
CVE-2023-52951 - Synology Note Station Client Cleartext Transmission of Sensitive Information

CVE ID :CVE-2023-52951 Published : June 3, 2026, 2:16 p.m. | 16 minutes ago Description :A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2022-49036 (CVSS 7.8)

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.

NVD (NIST)03 giu 2026
News
WordPress Plugin Vulnerability Exposes 500,000+ Websites to Privilege Escalation Attacks

WordPress Plugin Vulnerability Exposes 500,000+ Websites to Privilege Escalation Attacks A critical security flaw in the widely used Kirki WordPress plugin has exposed over 500,000 websites to potential account takeover attacks, with researchers warning that approximately 150,000 sites ar ... Read more Published Date: Jun 03, 2026 (2 days, 11 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-8206

CVEfeed Newsroom03 giu 2026
News
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI t ... Read more Published Date: Jun 03, 2026 (2 days, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-0257 CVE-2026-25588 CVE-2026-23631 CVE-2026-23479 CVE-2026-39987 CVE-2024-21182

CVEfeed Newsroom03 giu 2026
VulnerabilitàAlta
CVE-2026-35085 (CVSS 8.8)

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

NVD (NIST)03 giu 2026

Pagina 917 di 2575

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.