Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

43760 risultati

VulnerabilitàAlta
CVE-2026-100739 (CVSS 7.3)

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file viewresult.php. Performing a manipulation of the argument seno results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)2h fa
VulnerabilitàAlta
CVE-2026-94398 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service

CVE ID :CVE-2026-94398 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-94399 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service

CVE ID :CVE-2026-94399 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-94408 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service

CVE ID :CVE-2026-94408 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-94396 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service

CVE ID :CVE-2026-94396 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-94397 - Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service

CVE ID :CVE-2026-94397 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-94400 - Uncontrolled Resource Consumption in Kibana Leading to denial of service

CVE ID :CVE-2026-94400 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-72662 - Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data

CVE ID :CVE-2026-72662 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-78582 - Missing Authorization in Kibana Leading to Unauthorized Deletion of Data

CVE ID :CVE-2026-78582 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-82300 - Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

CVE ID :CVE-2026-82300 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-72668 - Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation

CVE ID :CVE-2026-72668 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa
VulnerabilitàAlta
CVE-2026-82294 - Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

CVE ID :CVE-2026-82294 Published : Sept. 26, 2026, 9:16 p.m. | 2 hours, 27 minutes ago Description :Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE3h fa

Pagina 1 di 3647

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.