Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

31833 risultati

VulnerabilitàAlta
CVE-2026-10843 (CVSS 7.2)

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.

NVD (NIST)04 giu 2026
VulnerabilitàCritica
CVE-2026-10840 (CVSS 9.6)

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.

NVD (NIST)04 giu 2026
VulnerabilitàAlta
CVE-2025-52611 - HCL iControl was affected by Unhandled Exception - Stack Trace Disclosure vulnerability

CVE ID :CVE-2025-52611 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems from one of the following: A missing or improperly initialized object. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-10804 - Streamlit Palette hashing.py weak hash

CVE ID :CVE-2026-10804 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Severity: 3.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-10803 - MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash

CVE ID :CVE-2026-10803 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Computation. This manipulation causes use of weak hash. It is possible to launch the attack on the local host. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Severity: 3.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2026-10802 - keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption

CVE ID :CVE-2026-10802 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The pull request to fix this issue awaits acceptance. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-52612 - HCL iControl was affected by Export CSV - CSV Injection vulnerability.

CVE ID :CVE-2025-52612 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-52609 - HCL iControl was affected by Missing Security Headers vulnerability.

CVE ID :CVE-2025-52609 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-52608 - HCL iControl was affected by Missing Cookie Attributes vulnerability.

CVE ID :CVE-2025-52608 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-12694 - Local Privilege Escalation in VPN Client

CVE ID :CVE-2025-12694 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
VulnerabilitàAlta
CVE-2025-52606 - HCL iControl was affected by Weak Input Validation vulnerability. .

CVE ID :CVE-2025-52606 Published : June 4, 2026, 12:16 p.m. | 16 minutes ago Description :HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE04 giu 2026
News
Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP c ... Read more Published Date: Jun 04, 2026 (3 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-3300

CVEfeed Newsroom04 giu 2026

Pagina 982 di 2653

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.