Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33284 risultati

VulnerabilitàAlta
CVE-2026-10178 - code-projects Online Music Site AdminEditAlbum.php sql injection

CVE ID :CVE-2026-10178 Published : May 31, 2026, 11:16 a.m. | 11 hours, 15 minutes ago Description :A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10179 - TRENDnet TEW-432BRP formSetWlanEncrypt stack-based overflow

CVE ID :CVE-2026-10179 Published : May 31, 2026, 11:16 a.m. | 11 hours, 15 minutes ago Description :A flaw has been found in TRENDnet TEW-432BRP 3.10B20. This issue affects the function formSetWlanEncrypt of the file /goform/formSetWlanEncrypt. This manipulation of the argument webpage causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10177 - Aider-AI Aider AWS EC2 Metadata Endpoint api_docs.py requests.get server-side request forgery

CVE ID :CVE-2026-10177 Published : May 31, 2026, 11:16 a.m. | 11 hours, 15 minutes ago Description :A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. It is suggested to install a patch to address this issue. The pull request to fix this issue awaits acceptance. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10176 - Aider-AI Aider Code Generation Workflow sql injection

CVE ID :CVE-2026-10176 Published : May 31, 2026, 10:16 a.m. | 12 hours, 16 minutes ago Description :A weakness has been identified in Aider-AI Aider 0.86.3. Affected by this issue is some unknown functionality of the component Code Generation Workflow. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10175 - Aider-AI Aider Architect Mode auth.py editor_coder.run code injection

CVE ID :CVE-2026-10175 Published : May 31, 2026, 9:16 a.m. | 13 hours, 16 minutes ago Description :A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10174 - Aider-AI Aider Pre-commit Hook args.py protection mechanism

CVE ID :CVE-2026-10174 Published : May 31, 2026, 9:16 a.m. | 11 hours, 16 minutes ago Description :A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation of the argument git-commit-verify leads to protection mechanism failure. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10173 - Orthanc Explorer 2 URL StudyList.vue cross site scripting

CVE ID :CVE-2026-10173 Published : May 31, 2026, 8:16 a.m. | 12 hours, 16 minutes ago Description :A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 21f78ce5da668bf5233efcd1896ec7c6e3b22eae. Applying a patch is the recommended action to fix this issue. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10172 - Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload

CVE ID :CVE-2026-10172 Published : May 31, 2026, 8:16 a.m. | 10 hours, 16 minutes ago Description :A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10171 - code-projects Online Music Site AdminUpdateAlbum.php sql injection

CVE ID :CVE-2026-10171 Published : May 31, 2026, 7:16 a.m. | 9 hours, 16 minutes ago Description :A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10170 - code-projects Visitor Management System phone_0.php sql injection

CVE ID :CVE-2026-10170 Published : May 31, 2026, 7:16 a.m. | 7 hours, 16 minutes ago Description :A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10168 - OUSL-GROUP-BrinaryBrains School Student Management System Parents.php marks resource injection

CVE ID :CVE-2026-10168 Published : May 31, 2026, 5:16 a.m. | 9 hours, 16 minutes ago Description :A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The manipulation of the argument param1 leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026
VulnerabilitàAlta
CVE-2026-10169 - OUSL-GROUP-BrinaryBrains School Student Management System Forgot Password Endpoint Login.php ajax_forgot_password password recovery

CVE ID :CVE-2026-10169 Published : May 31, 2026, 5:16 a.m. | 9 hours, 16 minutes ago Description :A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected by this vulnerability is the function ajax_forgot_password of the file application/controllers/Login.php of the component Forgot Password Endpoint. The manipulation of the argument email results in weak password recovery. The attack can be launched remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE31 mag 2026

Pagina 1168 di 2774

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.