Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

30976 risultati

VulnerabilitàAlta
CVE-2026-42321 - GLPI has stored XSS in asset locks

CVE ID :CVE-2026-42321 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-42317 - GLPI vulnerable to arbitrary files deletion by technician

CVE ID :CVE-2026-42317 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgrade to 10.0.25 or 11.0.7 to receive a patch. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-36748 - RockRMS Cross-Site Scripting

CVE ID :CVE-2026-36748 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-37462 - gobgp: BGPUpdate.DecodeFromBytes Integer Underflow Denial of Service

CVE ID :CVE-2026-37462 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-3276 - Potential DoS via quadratic complexity in unicodedata.normalize()

CVE ID :CVE-2026-3276 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-42318 - GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint

CVE ID :CVE-2026-42318 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. As a workaround, disable delete rights for User's planning. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-42320 - GLPI vulnerable to arbitrary file access

CVE ID :CVE-2026-42320 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-36574 - Wassimulator CactusViewer DLL Hijacking Privilege Escalation

CVE ID :CVE-2026-36574 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-36576 - openlabs docker-wkhtmltopdf-aas OS Command Injection

CVE ID :CVE-2026-36576 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2022-31114 - backpack/crud Vulnerable to Cross-site Scripting

CVE ID :CVE-2022-31114 Published : June 3, 2026, 4:16 p.m. | 16 minutes ago Description :backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.69, and 4.0.63 are vulnerable to cross-site scripting. An attacker could conduct a targeted phishing campaign, in order to trick users or admins into clicking a malicious link, which under very specific circumstances could give them information or possibly admin access. Versions 5.0.13, 4.1.69, and 4.0.63 patch the issue. As a workaround, manually look inside error views in `resources/views/errors` and output `e($exception->getMessage())` instead of `$exception->getMessage()`. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
News
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps. Any other app on the same ... Read more Published Date: Jun 03, 2026 (2 days, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-0257 CVE-2026-42832 CVE-2026-41102 CVE-2026-41101 CVE-2026-41100 CVE-2026-39987 CVE-2024-21182

CVEfeed Newsroom03 giu 2026
VulnerabilitàAlta
CVE-2026-8404 - Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware

CVE ID :CVE-2026-8404 Published : June 3, 2026, 2:16 p.m. | 2 hours, 16 minutes ago Description :An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026

Pagina 922 di 2582

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.