Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32328 risultati

VulnerabilitàAlta
CVE-2026-42673 - WordPress Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin <= 3.3.6 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-42673 Published : June 1, 2026, 5:16 p.m. | 1 hour, 15 minutes ago Description :Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a through 3.3.6. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-10273 (CVSS 7.3)

A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named cd68d102601320bd319d590b75f7652e66f0685f. It is recommended to apply a patch to fix this issue.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2026-10270 (CVSS 8.8)

A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.

NVD (NIST)01 giu 2026
VulnerabilitàAlta
CVE-2026-10118 (CVSS 7.8)

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

NVD (NIST)01 giu 2026
News
IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request

IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request IBM has disclosed a critical security vulnerability in its WebSphere Application Server ecosystem that could allow attackers to execute arbitrary code through specially crafted HTTP requests. The flaw ... Read more Published Date: Jun 01, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9739 CVE-2026-8633

CVEfeed Newsroom01 giu 2026
News
Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks

Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks A critical security vulnerability has been discovered in a widely used Magento caching plugin that allows attackers to remotely execute malicious code with no login, configuration changes, or admin ac ... Read more Published Date: Jun 01, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9739 CVE-2026-45247

CVEfeed Newsroom01 giu 2026
News
Critical MCP Toolbox Vulnerability Impacts Enterprise Database onnectors

Critical MCP Toolbox Vulnerability Impacts Enterprise Database onnectors A newly disclosed vulnerability, tracked as CVE-2026-9739, is raising security concerns across enterprise environments using MCP Toolbox, particularly those that rely on Server-Sent Events (SSE) for d ... Read more Published Date: Jun 01, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9739

CVEfeed Newsroom01 giu 2026
News
CVE-2026-40933 — Flowise: Authenticated RCE via MCP stdio Adapter

CVE-2026-40933 — Flowise: Authenticated RCE via MCP stdio Adapter June 1, 2026OverviewCVE-2026-40933 is a critical command injection vulnerability in Flowise, the drag-and-drop UI platform for building customized LLM flows. The vulnerability exists in the Model Cont ... Read more Published Date: Jun 01, 2026 (1 day, 15 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-0257 CVE-2026-40933 CVE-2026-30625

CVEfeed Newsroom01 giu 2026
VulnerabilitàAlta
CVE-2026-8931 - Critical RCE vulnerability in Disig Web Signer

CVE ID :CVE-2026-8931 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-48879 - WordPress AIWU plugin <= 1.4.17 - Privilege Escalation vulnerability

CVE ID :CVE-2026-48879 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-48866 - WordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerability

CVE ID :CVE-2026-48866 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026
VulnerabilitàAlta
CVE-2026-48865 - WordPress LearnPress plugin <= 4.3.6 - Reflected Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-48865 Published : June 1, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. This issue affects LearnPress: from n/a through 4.3.6. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 giu 2026

Pagina 1072 di 2694

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.