Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2026-41091Alta7.8
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- CVE-2026-8398Critica9.8
Un attacco alla supply chain ha compromesso i pacchetti di installazione ufficiali di DAEMON Tools Lite (versioni Windows dalla 12.5.0.2421 alla 12.5.0.2434), distribuiti dal sito web legittimo daemon-tools.cc tra l'8 aprile 2026 circa e il 5 maggio 2026. Gli attaccanti hanno ottenuto l'accesso non autorizzato all'infrastruttura di build o distribuzione del fornitore (AVB Disc Soft) e hanno trojanizzato tre binari: DTHelper.exe, DiscSoftBusServiceLite.exe e DTShellHlp.exe. Questi file sono stati firmati digitalmente con il legittimo certificato di code-signing di AVB Disc Soft, consentendo agli installer dannosi di apparire affidabili ed eludere il rilevamento basato su firma.
- CVE-2026-42897Alta8.1
Neutralizzazione impropria dell'input durante la generazione di pagine web ('cross-site scripting') in Microsoft Exchange Server consente a un attaccante non autorizzato di eseguire spoofing su una rete.
- CVE-2026-20182Critica10.0
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
- CVE-2026-6473Alta8.8
Un wraparound di interi in molteplici funzionalità del server PostgreSQL consente a un utente del database non privilegiato di indurre il server a sottodimensionare un'allocazione e a scrivere out-of-bounds. Ciò può eseguire codice arbitrario come utente del sistema operativo che esegue il database. Nelle applicazioni che passano input utente su scala di gigabyte alle funzioni di database pertinenti, il fornitore di input dell'applicazione può provocare un segmentation fault. Sono interessate le versioni precedenti a PostgreSQL 18.4, 17.10, 16.14, 15.18 e 14.23.
- CVE-2026-0257Critica9.1
Vulnerabilità di bypass dell'autenticazione nel portale GlobalProtect e nel gateway del software PAN-OS® di Palo Alto Networks consentono all'attaccante di aggirare le restrizioni di sicurezza e stabilire una connessione VPN non autorizzata. Panorama e Cloud NGFW non sono interessati da questi problemi.
- CVE-2026-41613Alta8.8
Session fixation in Visual Studio Code consente a un utente malintenzionato non autorizzato di elevare i privilegi in rete.
- CVE-2025-40949Critica9.1
È stata identificata una vulnerabilità in RUGGEDCOM ROX MX5000 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX MX5000RE (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1400 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1500 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1501 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1510 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1511 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1512 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1524 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1536 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX5000 (Tutte le versioni < V2.17.1). I dispositivi interessati non sanificano adeguatamente l'input fornito dall'utente nella funzionalità Scheduler dell'interfaccia Web, consentendo l'iniezione di comandi nel backend di pianificazione delle attività. Ciò potrebbe consentire a un utente malintenzionato remoto autenticato di eseguire comandi arbitrari con privilegi di root sul sistema operativo sottostante.
- CVE-2025-40948Media6.8
È stata identificata una vulnerabilità in RUGGEDCOM ROX MX5000 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX MX5000RE (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1400 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1500 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1501 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1510 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1511 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1512 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1524 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1536 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX5000 (Tutte le versioni < V2.17.1). I dispositivi interessati non convalidano correttamente l'input nell'interfaccia JSON-RPC del server web. Ciò potrebbe consentire a un utente malintenzionato remoto autenticato di leggere file arbitrari dal filesystem del sistema operativo sottostante con privilegi di root.
- CVE-2025-40947Alta7.5
È stata identificata una vulnerabilità in RUGGEDCOM ROX MX5000 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX MX5000RE (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1400 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1500 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1501 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1510 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1511 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1512 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1524 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX1536 (Tutte le versioni < V2.17.1), RUGGEDCOM ROX RX5000 (Tutte le versioni < V2.17.1). I dispositivi interessati non sanitizzano adeguatamente l'input fornito dall'utente durante il processo di installazione della chiave di funzionalità. Ciò potrebbe consentire a un utente malintenzionato remoto autenticato di iniettare comandi arbitrari, con conseguente esecuzione di codice remoto con privilegi di root sul sistema operativo sottostante.
- CVE-2026-34263Critica9.6
A causa di una configurazione impropria di Spring Security, SAP Commerce Cloud consente a un utente non autenticato di eseguire l'iniezione di input dannoso, con conseguente esecuzione di codice arbitrario lato server, con un impatto elevato sulla Confidenzialità, l'Integrità e la Disponibilità dell'applicazione.
- CVE-2026-45321Critica9.6
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.
- CVE-2026-42271Alta8.8
LiteLLM è un server proxy (AI Gateway) per chiamare le API LLM in formato OpenAI (o nativo). Dalla versione 1.74.2 fino a prima della versione 1.83.7, due endpoint utilizzati per visualizzare in anteprima un server MCP prima di salvarlo — POST /mcp-rest/test/connection e POST /mcp-rest/test/tools/list — accettavano una configurazione completa del server nel corpo della richiesta, inclusi i campi command, args e env utilizzati dal trasporto stdio. Quando chiamati con una configurazione stdio, gli endpoint tentavano di connettersi, avviando il comando fornito come sottoprocesso sull'host del proxy con i privilegi del processo del proxy. Gli endpoint erano protetti solo da una chiave API del proxy valida, senza alcun controllo del ruolo. Qualsiasi utente autenticato — inclusi i possessori di chiavi internal-user a basso privilegio — poteva quindi eseguire comandi arbitrari sull'host. Questo problema è stato corretto nella versione 1.83.7.
- CVE-2026-42208Critica9.8
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.
- CVE-2026-6973Alta7.2
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
- CVE-2026-0300Critica9.8
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
- CVE-2026-41940Critica9.8
Le versioni di cPanel e WHM successive alla 11.40 contengono una vulnerabilità di authentication bypass nel flusso di login che consente ad attaccanti remoti non autenticati di ottenere accesso non autorizzato al pannello di controllo.
- CVE-2026-31431Alta7.8
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
- CVE-2026-40933Critica9.9
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. The vulnerability lies in a bug in the input sanitization from the “Custom MCP” configuration in http://localhost:3000/canvas - where any user can add a new MCP, when doing so - adding a new MCP using stdio, the user can add any command, even though your code have input sanitization checks such as validateCommandInjection and validateArgsForLocalFileAccess, and a list of predefined specific safe commands - these commands, for example "npx" can be combined with code execution arguments ("-c touch /tmp/pwn") that enable direct code execution on the underlying OS. This vulnerability is fixed in 3.1.0.
- CVE-2026-35603Alta7.3
Claude Code è uno strumento di codifica agentico. Nelle versioni precedenti alla 2.1.75 su Windows, Claude Code caricava la configurazione predefinita a livello di sistema da C:\ProgramData\ClaudeCode\managed-settings.json senza convalidare la proprietà della directory o le autorizzazioni di accesso. Poiché la directory ProgramData è scrivibile per impostazione predefinita da utenti non amministrativi e la sottodirectory ClaudeCode non era pre-creata né con accesso limitato, un utente locale con privilegi limitati poteva creare tale directory e inserire un file di configurazione dannoso che sarebbe stato caricato automaticamente per qualsiasi utente che avesse avviato Claude Code sulla stessa macchina. Lo sfruttamento avrebbe richiesto un sistema Windows multiutente condiviso e che un utente vittima avviasse Claude Code dopo l'inserimento della configurazione dannosa. Questo problema è stato corretto nella versione 2.1.75.
This product uses the NVD API but is not endorsed or certified by the NVD.