Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

31063 risultati

VulnerabilitàAlta
CVE-2026-35078 (CVSS 8.1)

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

NVD (NIST)03 giu 2026
VulnerabilitàAlta
CVE-2026-35077 (CVSS 8.1)

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

NVD (NIST)03 giu 2026
VulnerabilitàAlta
CVE-2026-35076 (CVSS 8.1)

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

NVD (NIST)03 giu 2026
VulnerabilitàCritica
CVE-2026-35075 (CVSS 9.8)

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

NVD (NIST)03 giu 2026
News
Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections

Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections A critical vulnerability in Apache ActiveMQ has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross ... Read more Published Date: Jun 03, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-49157 CVE-2026-42253

CVEfeed Newsroom03 giu 2026
News
Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege

Ivanti ITSM Vulnerability Lets Attackers Gain Admin Privilege Ivanti has disclosed a high-severity vulnerability in its Ivanti Neurons for ITSM platform that could allow attackers with valid credentials to escalate privileges and gain full administrative access. ... Read more Published Date: Jun 03, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9614

CVEfeed Newsroom03 giu 2026
News
Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing

Laravel CRLF Injection Vulnerability Enables an Attacker to Interfere with Outbound Email Processing A high-severity CRLF injection vulnerability in the Laravel framework, tracked as CVE-2026-48019, could allow attackers to interfere with outbound email processing in affected applications. The issue ... Read more Published Date: Jun 03, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom03 giu 2026
VulnerabilitàAlta
CVE-2026-41032 (CVSS 7.5)

It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

NVD (NIST)03 giu 2026
VulnerabilitàAlta
CVE-2025-15655 - WordPress School Management plugin <= 93.2.0 - SQL Injection vulnerability

CVE ID :CVE-2025-15655 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2025-14774 - Communication analysis between the Card Reader and TP2CardReaderService daemon

CVE ID :CVE-2025-14774 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2026-41032 - Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers

CVE ID :CVE-2026-41032 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026
VulnerabilitàAlta
CVE-2025-15656 - WordPress School Management plugin <= 93.2.0 - Privilege Escalation vulnerability

CVE ID :CVE-2025-15656 Published : June 3, 2026, 11:16 a.m. | 1 hour, 16 minutes ago Description :Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 giu 2026

Pagina 933 di 2589

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.