Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32031 risultati

VulnerabilitàAlta
CVE-2025-53209 - WordPress Masteriyo LMS PRO plugin <= 2.20.0 - Privilege Escalation Vulnerability

CVE ID :CVE-2025-53209 Published : June 2, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2025-53302 - WordPress Constructor theme <= 1.6.5 - Broken Access Control Vulnerability

CVE ID :CVE-2025-53302 Published : June 2, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Constructor: from n/a through 1.6.5. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2025-52759 - WordPress Accordion FAQ plugin <= 2.2.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2025-52759 Published : June 2, 2026, 10:16 a.m. | 2 hours, 16 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS. This issue affects Accordion FAQ: from n/a through 2.2.1. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-1784 (CVSS 8.8)

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.

NVD (NIST)02 giu 2026
News
Google waarschuwt voor actief misbruikt beveiligingslek in Androidtelefoons

Google waarschuwt voor actief misbruikt beveiligingslek in Androidtelefoons Google waarschuwt voor een actief misbruikte kwetsbaarheid in Androidtelefoons en heeft updates uitgebracht om het probleem te verhelpen. Daarnaast zijn ook patches verschenen voor twee kritieke bevei ... Read more Published Date: Jun 02, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-48595 CVE-2025-65018 CVE-2025-64720

CVEfeed Newsroom02 giu 2026
News
Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack

Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack A newly discovered software supply chain campaign, dubbed Miasma, has emerged as the latest evolution of the Shai-Hulud supply chain attack, compromising several redhat-cloud-services npm packages to ... Read more Published Date: Jun 02, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom02 giu 2026
VulnerabilitàAlta
CVE-2026-9722 - Laiser Tag <= 1.2.5 - Cross-Site Request Forgery to Plugin Settings Update via Settings Form

CVE ID :CVE-2026-9722 Published : June 2, 2026, 9:16 a.m. | 1 hour, 16 minutes ago Description :The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the addOptionsPageFields function. This makes it possible for unauthenticated attackers to update the plugin's settings, including the API key, tag blacklist, relevance threshold, batch size, and tagging toggles, via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-8422 - Remove meta boxes per user role <= 1.01 - Cross-Site Request Forgery to Settings Update

CVE ID :CVE-2026-8422 Published : June 2, 2026, 9:16 a.m. | 1 hour, 16 minutes ago Description :The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated attackers to modify or reset the plugin's per-role meta box visibility settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-1451 - rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'a' Parameter

CVE ID :CVE-2026-1451 Published : June 2, 2026, 7:48 a.m. | 44 minutes ago Description :The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-9730 - Remove NoFollow Commenter URL <= 1.0 - Cross-Site Request Forgery to Settings Update

CVE ID :CVE-2026-9730 Published : June 2, 2026, 9:16 a.m. | 3 hours, 16 minutes ago Description :The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify the plugin's comment-display setting via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-3620 - Word Replacer <= 0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Replacement' Parameter

CVE ID :CVE-2026-3620 Published : June 2, 2026, 9:16 a.m. | 1 hour, 16 minutes ago Description :The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026
VulnerabilitàAlta
CVE-2026-9599 - Tectite Forms <= 1.3 - Cross-Site Request Forgery to Settings Update

CVE ID :CVE-2026-9599 Published : June 2, 2026, 9:16 a.m. | 1 hour, 16 minutes ago Description :The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the tectite_forms_button option, via a forged request via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 giu 2026

Pagina 1032 di 2670

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.