Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

31704 risultati

VulnerabilitàAlta
CVE-2026-49941 - Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses

CVE ID :CVE-2026-49941 Published : June 4, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a 32-bit or 128-bit netmask. If the argument was not a well-formed IP address, then this would lead to indefinite recursion. An attacker could use this to cause a denial of service. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-49940 - Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks

CVE ID :CVE-2026-49940 Published : June 4, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parsed as numbers. This could allow network masks to accept larger networks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-46741 - Etsy::StatsD versions through 1.002002 for Perl allow metric injections

CVE ID :CVE-2026-46741 Published : June 4, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note that the git repository contains an unreleased version with the gauge and set methods that also do not check for potential metric injections. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-46739 - Net::Statsd versions before 0.13 for Perl allow metric injections

CVE ID :CVE-2026-46739 Published : June 4, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. The update_stats (used for updating counters) and gauge methods do not check that values are numeric (which would block metric injection). Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-67446 - Neterbit NW-431F Router Authentication Bypass via Predictable Cookie

CVE ID :CVE-2025-67446 Published : June 4, 2026, 5:16 p.m. | 1 hour, 16 minutes ago Description :Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication schema and gain unauthorized access to admin functionalities. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
News
CISA Warns of critical Magento Cache Warmer RCE flaw Exploited in Attacks

CISA Warns of critical Magento Cache Warmer RCE flaw Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical remote code execution vulnerability affecting the Mirasvit Full Page Cache Warmer extensi ... Read more Published Date: Jun 04, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45247

CVEfeed Newsroom04 giu 2026
News
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, a ... Read more Published Date: Jun 04, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20230 CVE-2026-45659 CVE-2026-0257 CVE-2026-39987 CVE-2026-20045 CVE-2025-20309 CVE-2024-21182

CVEfeed Newsroom04 giu 2026
VulnerabilitàAlta
CVE-2026-7774 - tarfile.data_filter path traversal bypass allows writing outside the extraction directory

CVE ID :CVE-2026-7774 Published : June 4, 2026, 4:16 p.m. | 16 minutes ago Description :tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-5228 (CVSS 8.8)

Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.

NVD (NIST)04 giu 2026
VulnerabilitàAlta
CVE-2026-43985 - Taultulli has CSRF in /configUpdate via missing anti-CSRF and method restriction that allows admin credential takeover

CVE ID :CVE-2026-43985 Published : June 4, 2026, 4:16 p.m. | 16 minutes ago Description :Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce `POST` and does not use any anti-CSRF token. In the default form and JWT-based authentication mode, the administrator session cookie is issued with `SameSite=Lax`, which still permits top-level cross-site navigation requests. An attacker can exploit this by luring a logged-in administrator to a malicious page that submits a cross-site request to `/configUpdate` and overwrites the local administrator username and password. The attacker can then sign in directly with the chosen credentials and take over the Tautulli administrative interface. Version 2.17.1 patches the issue. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-43986 - Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replay

CVE ID :CVE-2026-43986 Published : June 4, 2026, 4:16 p.m. | 16 minutes ago Description :Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-side image fetch logic used by authenticated image proxying. A low-privilege guest user can seed a malicious external image URL into this lookup table and then trigger server-side fetches through a fully unauthenticated endpoint. This turns an authenticated SSRF primitive into a persistent unauthenticated SSRF gadget. Once the malicious hash entry exists, any external user can request `/image/.png` and cause the PMS or Tautulli host to fetch an arbitrary attacker-chosen URL. Version 2.17.1 patches the issue. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-44393 - OpenStack Oslo.messaging RabbitMQ TLS Man-in-the-Middle Vulnerability

CVE ID :CVE-2026-44393 Published : June 4, 2026, 4:16 p.m. | 16 minutes ago Description :An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does not pass the expected broker hostname into the underlying TLS stack. Any certificate signed by the deployment CA is accepted regardless of hostname, allowing an attacker who can intercept control-plane traffic to impersonate the RabbitMQ broker and perform a man-in-the-middle attack on RPC and notification traffic. All OpenStack services using oslo.messaging with RabbitMQ over TLS are affected. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026

Pagina 965 di 2642

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.