Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

31035 risultati

VulnerabilitàAlta
CVE-2025-41259 - SWUpdate Untrusted Script Execution via Signed Update TOCTOU

CVE ID :CVE-2025-41259 Published : June 3, 2026, 11:01 a.m. | 1 hour, 30 minutes ago Description :SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
News
Vulnerabilities in school-management-system software

Vulnerabilities in school-management-system software Vulnerabilities in school-management-system software CVE ID CVE-2026-47324 Publication date 03 June 2026 Vendor ProjectsAndPrograms Product school-management-system Vulnerable versions 6b6fae5 Vulnera ... Read more Published Date: Jun 03, 2026 (2 days, 1 hour ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom03 giu 2026
VulnerabilitàAlta
CVE-2026-10722 - cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow

CVE ID :CVE-2026-10722 Published : June 3, 2026, 10:45 a.m. | 1 hour, 47 minutes ago Description :A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
News
Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker. Like in the case of CVE-2026-33829, which impacted the ... Read more Published Date: Jun 03, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-0257 CVE-2026-33829 CVE-2026-39987 CVE-2024-21182 CVE-2023-35636

CVEfeed Newsroom03 giu 2026
VulnerabilitàAlta
CVE-2026-4035 - Environment Variable Resolution Vulnerability in mlflow/mlflow

CVE ID :CVE-2026-4035 Published : June 3, 2026, 9:16 a.m. | 3 hours, 16 minutes ago Description :A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's environment during runtime. The resolved secrets are then sent in provider authentication headers to the configured upstream `api_base`. This vulnerability can be exploited by low-privileged authenticated users in basic-auth deployments or by unauthenticated users in default deployments without `basic-auth`. The impact includes potential leakage of sensitive credentials such as cloud artifact credentials (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`), which could lead to artifact poisoning and cross-boundary code execution in downstream environments. The issue is fixed in version 3.11.0. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2025-15654 - WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2025-15654 Published : June 3, 2026, 9:16 a.m. | 3 hours, 16 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This issue affects Prague: from n/a through 2.2.8. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
News
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerabil ... Read more Published Date: Jun 03, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45659 CVE-2026-0257 CVE-2026-39987 CVE-2025-53020 CVE-2024-21182 CVE-2016-6581 CVE-2016-8740 CVE-2016-1546

CVEfeed Newsroom03 giu 2026
VulnerabilitàAlta
CVE-2026-5078 - morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

CVE ID :CVE-2026-5078 Published : June 3, 2026, 8:16 a.m. | 4 hours, 16 minutes ago Description :Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header containing CR or LF bytes to inject forged log lines, breaking the one-request-per-line structure of access logs and enabling log forgery against downstream log consumers. The built-in combined, common, default, and short formats are affected, as well as any custom format that references :remote-user. Affected versions: morgan 1.2.0 through 1.10.1. Patches: upgrade to morgan 1.11.0, which neutralizes control characters in the :remote-user token output. Workarounds: use a custom format string that does not include :remote-user. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
News
Microsoft 365 Android Apps Account Takeover Vulnerability Impacted Billions of Android Users

Microsoft 365 Android Apps Account Takeover Vulnerability Impacted Billions of Android Users A single forgotten development flag left active in production code silently handed Microsoft account tokens to any app on an Android device, exposing billions of users across six major Microsoft 365 a ... Read more Published Date: Jun 03, 2026 (2 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-41102 CVE-2026-41101 CVE-2026-41100

CVEfeed Newsroom03 giu 2026
News
VS meldt misbruik van vier jaar oud beveiligingslek in Linux-kernel

VS meldt misbruik van vier jaar oud beveiligingslek in Linux-kernel Aanvallers maken actief misbruik van een vier jaar oude kwetsbaarheid in de Linux-kernel of hebben dit gedaan, zo waarschuwt het Amerikaanse cyberagentschap CISA. Het gaat om CVE-2022-0492, waardoor e ... Read more Published Date: Jun 03, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2022-0492

CVEfeed Newsroom03 giu 2026
News
Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers

Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers A newly disclosed flaw in the Windows search URI handler can silently leak NTLMv2 hashes to attacker-controlled servers with nothing more than a single link click. This behavior is the same bug class ... Read more Published Date: Jun 03, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33829

CVEfeed Newsroom03 giu 2026
News
HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora A newly disclosed remote denial-of-service exploit dubbed “HTTP/2 Bomb” targets the default HTTP/2 configurations of the world’s most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, E ... Read more Published Date: Jun 03, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom03 giu 2026

Pagina 932 di 2587

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.