News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
31864 risultati
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited ... Read more Published Date: Jun 04, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45247 CVE-2026-45659 CVE-2026-0257 CVE-2026-39987 CVE-2024-21182
CVE ID :CVE-2026-50206 Published : June 4, 2026, 7:16 a.m. | 3 hours, 16 minutes ago Description :Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-50205 Published : June 4, 2026, 7:16 a.m. | 3 hours, 16 minutes ago Description :System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49193 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49192 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49191 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49194 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49202 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49203 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49204 Published : June 4, 2026, 7:16 a.m. | 3 hours, 16 minutes ago Description :Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49190 Published : June 4, 2026, 7:16 a.m. | 1 hour, 16 minutes ago Description :The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-50219 Published : June 4, 2026, 6:16 a.m. | 2 hours, 16 minutes ago Description :libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 988 di 2656