News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
31063 risultati
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections A critical vulnerability in Apache ActiveMQ has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross ... Read more Published Date: Jun 03, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-49157 CVE-2026-42253
Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege Ivanti has disclosed a high-severity vulnerability in its Ivanti Neurons for ITSM platform that could allow attackers with valid credentials to escalate privileges and gain full administrative access. ... Read more Published Date: Jun 03, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9614
Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing A high-severity CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to interfere with outbound email processing in affected applications. The issue ... Read more Published Date: Jun 03, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article.
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
CVE ID :CVE-2025-15655 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-14774 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41032 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-15656 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 933 di 2589