News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
31035 risultati
Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections A critical vulnerability in Apache ActiveMQ has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross ... Read more Published Date: Jun 03, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-49157 CVE-2026-42253
Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege Ivanti has disclosed a high-severity vulnerability in its Ivanti Neurons for ITSM platform that could allow attackers with valid credentials to escalate privileges and gain full administrative access. ... Read more Published Date: Jun 03, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9614
Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing A high-severity CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to interfere with outbound email processing in affected applications. The issue ... Read more Published Date: Jun 03, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article.
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
CVE ID :CVE-2025-14774 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-47065 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which performs Class.forName(intf, false, latestUserDefinedLoader()) for EACH interface name and constructs the proxy class — bypassing the accepted classes list . ZDRES-233: Class.forName(name, initialize=true, classLoader) in readClassDescriptor Triggers Static Initialiser of Allow-Listed Classes Assessment: Fully addressed. For ANY class on the allow-list, deserialising a stream that names it triggers the class’s (static initialiser) BEFORE any instance is constructed. This means an attacker who supplies a class name on the allow-list (e.g., the developer wrote accept(“com.myapp.*") , attacker supplies com.myapp.SomeClass ) causes of SomeClass — and many real-world classes have side-effecting static initialisers Both issues have been fixed. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41032 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-15656 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-15655 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-14772 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-14773 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-14771 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 931 di 2587