Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

31831 risultati

VulnerabilitàAlta
CVE-2026-38570 - bacnet_stack Out-of-bounds Read

CVE ID :CVE-2026-38570 Published : June 4, 2026, 4:16 p.m. | 16 minutes ago Description :bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-10815 - LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization

CVE ID :CVE-2026-10815 Published : June 4, 2026, 4:16 p.m. | 16 minutes ago Description :A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in missing authorization. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-10868 - MISP user edit endpoint mass assignment vulnerability allows unauthorized user account modification

CVE ID :CVE-2026-10868 Published : June 4, 2026, 4:16 p.m. | 16 minutes ago Description :A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from request data. An authenticated attacker could craft a modified request containing another user identifier, potentially causing updates to be applied to an unintended user account. Depending on the editable fields and the attacker’s privileges, this could allow unauthorized modification of user account attributes and impact account integrity. The issue was addressed by explicitly removing the User.id field from request data before processing the user edit operation. Severity: 9.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-10814 - milvus-io milvus Grantee ID Hash kv_catalog.go weak hash

CVE ID :CVE-2026-10814 Published : June 4, 2026, 4:16 p.m. | 16 minutes ago Description :A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Handler. The manipulation leads to use of weak hash. The attack needs to be performed locally. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 3d932f1c3e065351c4440c27abe1e6479752544d. Applying a patch is the recommended action to fix this issue. Severity: 4.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-10813 - LMCache KV Cache utils.py hex_hash_to_int16 weak hash

CVE ID :CVE-2026-10813 Published : June 4, 2026, 4:16 p.m. | 16 minutes ago Description :A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance. Severity: 3.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
News
CISA adds Three Vulnerabilities to KEV Catalog

CISA adds Three Vulnerabilities to KEV Catalog OverviewCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation — CVE-2022-0492, a Linux Kernel Improper Authentication v ... Read more Published Date: Jun 04, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-48595 CVE-2026-45247 CVE-2022-0492

CVEfeed Newsroom04 giu 2026
VulnerabilitàAlta
CVE-2026-47707 - Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification

CVE ID :CVE-2026-47707 Published : June 4, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a dos via resource exhaustion. Version 0.315.7 contains a fix for the issue. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-45739 - Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs

CVE ID :CVE-2026-45739 Published : June 4, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization: Bearer `, the value could become visible in browser history, copied links, and server/proxy/CDN access logs after a page reload or shared request. Version 0.315.4 patches the issue. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-47706 - Strawberry GraphQL has a Circular Fragment Reference DOS

CVE ID :CVE-2026-47706 Published : June 4, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determine_depth function enters an infinite recursion, leading to a RecursionError and crashing the validation process. Version 0.315.7 patches the issue. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-36180 - GNCC GP5 Runtime Integrity Bypass Leading to File System Modification

CVE ID :CVE-2026-36180 Published : June 4, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot session via a bind-mount attack. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-36178 - GNCC GP5: Cryptographic Material Leakage After Factory Reset

CVE ID :CVE-2026-36178 Published : June 4, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive user data. Severity: 4.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-36176 - GNCC GP5 Plaintext Storage of Backblaze B2 Upload URLs

CVE ID :CVE-2026-36176 Published : June 4, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026

Pagina 977 di 2653

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.