RADAR / LIVE
Trova il bollettino che ti riguarda
Cerca una CVE, un’azienda, un prodotto o una tecnologia. Apri direttamente il bollettino della fonte.
50ultimi bollettiniUltimo controllo: 06/10/26, 20:19
Ogni 4 ore circa
Ogni 4 ore circa
La lista si filtra nel browser mentre scrivi. Premendo Cerca invii la ricerca a Duckerside, NVD e registro CVE: non inserire dati personali.
Ultimi 50 bollettini
Dal più recente · Fonti originali
DataFonte / gravitàBollettinoLink
CISA AdvisoryMedia 6,5Hitachi Energy REB500NuovoView CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) aApriCISA AdvisoryAlta 8,1Hitachi Energy Asset SuiteNuovoView CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause coApriCISA AdvisoryAlta 7,7Johnson Controls EasyIO FGNuovoView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmApriCISA AdvisoryAlta 8,8Hitachi Energy SOINuovoView CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out varApriCISA AdvisoryCritica 9,8Savannah lwIP SMTP clientNuovoView CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are ApriCISA AdvisoryCritica 9,8Hitachi Energy RTU500NuovoView CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associatApriCISA AdvisoryNon indicataCISA Adds One Known Exploited Vulnerability to CatalogNuovoCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the BoApriCISA KEV / NVDAlta 8,7Citrix: NetScaler — CVE-2026-88779Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a deApriCISA AdvisoryNon indicataCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability CVE-2026-102490 ZaApriCISA KEV / NVDCritica 9,4Zammad GmbH: Zammad — CVE-2026-102490Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.ApriCISA KEV / NVDCritica 9,4Zammad GmbH: Zammad — CVE-2026-102489Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.ApriCISA AdvisoryNon indicataCISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerabiApriCISA AdvisoryBassa 3,5Johnson Controls EasyIO Neo Series EC and CW ControllersView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of ApriCISA AdvisoryMedia 5,4Johnson Controls EasyIO Neo Series EC and CW ControllersView CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls EasyIOApriCISA AdvisoryCritica 9,8Armatura LLC Armatura OneView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain contApriCISA AdvisoryMedia 6,4ABB Protection and Control IED Manager PCM600View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: ApriCISA AdvisoryAlta 8,8CISA MalcolmView CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site ApriCISA AdvisoryAlta 7,7Meari IoT Cloud Platform OpenAPI ServiceView CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, oApriCISA AdvisoryCritica 9,4Monta monta.appView CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-serviApriCISA KEV / NVDCritica 9,8Fortinet: FortiMail — CVE-2026-104286Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crApriCISA AdvisoryNon indicataCISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability This type of vApriCISA KEV / NVDCritica 9,8Cisco: Catalyst SD-WAN Manager — CVE-2026-76504Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoApriCISA AdvisoryAlta 7,5Lantronix G520 Series Cellular GatewayView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular GatApriCISA AdvisoryCritica 9,8MikroTik RouterOSView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS CVApriCISA AdvisoryAlta 7,4Baicells Nova 430HView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition. The following versions of Baicells Nova 430H are affecApriCISA AdvisoryCritica 10,0VIVOTEK Camera FirmwareView CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera systApriCISA AdvisoryCritica 9,8Anjvision YSSD-RTMP-H5View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device. The folloApriCISA AdvisoryCritica 10,0Toptech TMS7 and TopHATView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code. The following versions of Toptech TMS7 and TopHAT are affected: TMS7 7.6.3 (CVApriCISA AdvisoryNon indicataCISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability This type of ApriCISA AdvisoryCritica 10,0Viidure Dashcam Android ApplicationView CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire plApriCISA KEV / NVDAlta 8,8Apple: Multiple Products — CVE-2026-86950Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.ApriCISA AdvisoryNon indicataCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability CVE-20ApriCISA AdvisoryNon indicataCritical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, GatewayUpdate October 2, 2026: CISA has updated this Alert to provide a SIGMA detection rule resource to help identify potentially suspicious activity. CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affectiApriCISA KEV / NVDCritica 9,5Citrix: NetScaler — CVE-2026-88772Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of serviceApriCISA KEV / NVDCritica 9,5Citrix: NetScaler — CVE-2026-88771Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.ApriCISA AdvisoryNon indicataCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 MikrApriCISA AdvisoryNon indicataCISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability This type of vulneraApriCISA KEV / NVDMedia 6,9MikroTik: RouterOS — CVE-2026-67279Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to ApriCISA KEV / NVDAlta 8,8Microsoft: SharePoint — CVE-2026-65660Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.ApriCISA KEV / NVDAlta 8,1WordPress: Core — CVE-2026-87902WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directorieApriCISA AdvisoryCritica 9,1Siemens Mendix Runtime (Update A)View CSAF Summary This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute. The following versions of Siemens Mendix RuntimApriCISA ICSCritica 9,4Eufy Omni C20, Omni X10 ProView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code. The following versions of Eufy Omni C20, Omni X10 Pro are affected: Omni ApriCISA ICSAlta 8,8Botslab G980H DashcamsView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device ApriCISA KEV / NVDCritica 10,0WSO2: Multiple Products — CVE-2026-5430WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. ApriCISA KEV / NVDCritica 9,1Adobe: Commerce and Magento — CVE-2026-71362Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. ApriCISA ICSAlta 7,8Siemens SIPLUS and SIMATIC ProductsView CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preApriCISA ICSCritica 9,8lwIP TCP/IP Stack MQTT Client ApplicationView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device. The following versions of lwIP TCP/IP Stack MQTT Client Application are affected: MQTT ClApriCISA ICSAlta 8,8lwIP (Lightweight IP)View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (LightwApriCISA ICSCritica 9,0Siemens Siveillance ControlView CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability alloApriCISA ICSAlta 8,2Siemens Desigo CC familyView CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documenApri