Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33431 risultati

VulnerabilitàAlta
CVE-2018-25415 (CVSS 8.2)

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. Attackers can send GET requests to director.php with crafted SQL payloads in the director parameter to extract sensitive database information including usernames, database names, and version details.

NVD (NIST)30 mag 2026
VulnerabilitàAlta
CVE-2018-25414 (CVSS 8.2)

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. Attackers can send GET requests to actor.php with crafted SQL payloads in the actor parameter to extract sensitive database information including usernames, database names, and version details.

NVD (NIST)30 mag 2026
VulnerabilitàAlta
CVE-2018-25413 (CVSS 8.2)

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to search.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.

NVD (NIST)30 mag 2026
VulnerabilitàAlta
CVE-2018-25417 - AiOPMSD Final 1.0.0 SQL Injection via quality.php

CVE ID :CVE-2018-25417 Published : May 30, 2026, 4:17 p.m. | 8 hours, 15 minutes ago Description :AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php with crafted SQL payloads in the quality parameter to extract sensitive database information including usernames, database names, and version details. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mag 2026
VulnerabilitàAlta
CVE-2018-25418 - AiOPMSD Final 1.0.0 SQL Injection via year.php

CVE ID :CVE-2018-25418 Published : May 30, 2026, 4:17 p.m. | 8 hours, 15 minutes ago Description :AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. Attackers can send GET requests to year.php with crafted SQL payloads in the year parameter to extract sensitive database information including usernames, database names, and version details. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mag 2026
VulnerabilitàAlta
CVE-2018-25414 - AiOPMSD Final 1.0.0 SQL Injection via actor.php

CVE ID :CVE-2018-25414 Published : May 30, 2026, 4:17 p.m. | 6 hours, 15 minutes ago Description :AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. Attackers can send GET requests to actor.php with crafted SQL payloads in the actor parameter to extract sensitive database information including usernames, database names, and version details. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mag 2026
VulnerabilitàAlta
CVE-2018-25413 - AiOPMSD Final 1.0.0 SQL Injection via search.php

CVE ID :CVE-2018-25413 Published : May 30, 2026, 4:17 p.m. | 6 hours, 15 minutes ago Description :AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to search.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mag 2026
VulnerabilitàAlta
CVE-2018-25415 - AiOPMSD Final 1.0.0 SQL Injection via director Parameter

CVE ID :CVE-2018-25415 Published : May 30, 2026, 4:17 p.m. | 8 hours, 15 minutes ago Description :AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. Attackers can send GET requests to director.php with crafted SQL payloads in the director parameter to extract sensitive database information including usernames, database names, and version details. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mag 2026
VulnerabilitàAlta
CVE-2018-25416 - AiOPMSD Final 1.0.0 SQL Injection via country.php

CVE ID :CVE-2018-25416 Published : May 30, 2026, 4:17 p.m. | 8 hours, 15 minutes ago Description :AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. Attackers can send GET requests to country.php with crafted SQL payloads in the country parameter to extract sensitive database information including usernames, database names, and version details. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mag 2026
VulnerabilitàAlta
CVE-2018-25419 - AiOPMSD Final 1.0.0 SQL Injection via genre.php

CVE ID :CVE-2018-25419 Published : May 30, 2026, 4:17 p.m. | 8 hours, 15 minutes ago Description :AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter. Attackers can send GET requests to genre.php with crafted SQL payloads in the genre parameter to extract sensitive database information including usernames, database names, and version details. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mag 2026
VulnerabilitàCritica
CVE-2018-25412 (CVSS 9.8)

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.

NVD (NIST)30 mag 2026
VulnerabilitàAlta
CVE-2018-25411 (CVSS 8.2)

MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to email.php with crafted SQL payloads in the 'id' parameter to extract sensitive database information including table and column names.

NVD (NIST)30 mag 2026

Pagina 1186 di 2786

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.