Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

23813 risultati

VulnerabilitàAlta
CVE-2026-57649 - WordPress Shoppable Images Lite plugin <= 1.3 - Broken Access Control vulnerability

CVE ID :CVE-2026-57649 Published : June 26, 2026, 2:53 p.m. | 51 minutes ago Description :Subscriber Broken Access Control in Shoppable Images Lite Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-57648 - WordPress Nelio Content plugin <= 4.3.4 - Broken Access Control vulnerability

CVE ID :CVE-2026-57648 Published : June 26, 2026, 2:53 p.m. | 51 minutes ago Description :Contributor Broken Access Control in Nelio Content Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-57646 - WordPress Majestic Support plugin <= 1.1.7 - Insecure Direct Object References (IDOR) vulnerability

CVE ID :CVE-2026-57646 Published : June 26, 2026, 2:53 p.m. | 51 minutes ago Description :Subscriber Insecure Direct Object References (IDOR) in Majestic Support Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-57647 - WordPress Panorama Viewer – 360 Degree Image + Video Viewer plugin <= 1.6.1 - Local File Inclusion vulnerability

CVE ID :CVE-2026-57647 Published : June 26, 2026, 2:53 p.m. | 51 minutes ago Description :Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-57645 - WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability

CVE ID :CVE-2026-57645 Published : June 26, 2026, 2:53 p.m. | 51 minutes ago Description :newsletters_subscribers Broken Access Control in Newsletters Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-57644 - WordPress Restaurant Menu by MotoPress plugin <= 2.4.10 - SQL Injection vulnerability

CVE ID :CVE-2026-57644 Published : June 26, 2026, 2:53 p.m. | 51 minutes ago Description :Contributor SQL Injection in Restaurant Menu by MotoPress Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-57643 - WordPress WP Post Author plugin <= 3.9.1 - SQL Injection vulnerability

CVE ID :CVE-2026-57643 Published : June 26, 2026, 2:53 p.m. | 51 minutes ago Description :Contributor SQL Injection in WP Post Author Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-57642 - WordPress Gallery plugin <= 4.7.8 - SQL Injection vulnerability

CVE ID :CVE-2026-57642 Published : June 26, 2026, 2:53 p.m. | 51 minutes ago Description :Contributor SQL Injection in Gallery Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
News
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and ... Read more Published Date: Jun 26, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-12958 CVE-2026-12957 CVE-2026-11645 CVE-2026-30615 CVE-2025-59536 CVE-2025-54136

CVEfeed Newsroom1g fa
VulnerabilitàAlta
CVE-2026-57940 - HTMLy Server-Side Request Forgery

CVE ID :CVE-2026-57940 Published : June 26, 2026, 1:08 p.m. | 37 minutes ago Description :HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to file_get_contents() without any validation. An authenticated attacker with administrative privileges can exploit this by entering a crafted URL (e.g., http://dnslog.example.com/ , file:///etc/passwd, or http://169.254.169.254 in cloud contexts) via Tools -> Import RSS. The server will then make a request to the attacker-controlled target. Severity: 2.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-53914 - JetBrains Kotlin Unsafe Deserialization

CVE ID :CVE-2026-53914 Published : June 26, 2026, 1:01 p.m. | 44 minutes ago Description :In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
News
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-e ... Read more Published Date: Jun 26, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-46331 CVE-2026-11645

CVEfeed Newsroom1g fa

Pagina 12 di 1985

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.