Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33510 risultati

VulnerabilitàAlta
CVE-2026-45663 - Dokploy: Remote Code Execution via destinationPath in Container File Upload

CVE ID :CVE-2026-45663 Published : May 29, 2026, 4:16 p.m. | 15 minutes ago Description :Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly interpolated into a shell command string. By including shell metacharacters such as ; or ", an attacker can escape the intended docker cp command and execute arbitrary OS commands on the Dokploy host. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mag 2026
VulnerabilitàAlta
CVE-2026-45662 - Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)

CVE ID :CVE-2026-45662 Published : May 29, 2026, 4:16 p.m. | 15 minutes ago Description :Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same file, the docker login command correctly uses shEscape() to prevent command injection. This inconsistency creates a command injection vulnerability when deleting a registry with a crafted registryUrl. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mag 2026
VulnerabilitàAlta
CVE-2026-44962 - Plesk XPath Injection Vulnerability

CVE ID :CVE-2026-44962 Published : May 29, 2026, 4:16 p.m. | 15 minutes ago Description :Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mag 2026
VulnerabilitàAlta
CVE-2026-35674 (CVSS 8.8)

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to bypass operator.approvals and operator.admin scope requirements, enabling unauthorized plugin, config, MCP, allowlist, and ACP mutations.

NVD (NIST)29 mag 2026
VulnerabilitàAlta
CVE-2026-35630 (CVSS 8)

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval requests without proper authorization.

NVD (NIST)29 mag 2026
VulnerabilitàAlta
CVE-2026-35673 - OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes

CVE ID :CVE-2026-35673 Published : May 29, 2026, 4:16 p.m. | 16 minutes ago Description :OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can bypass private-network SSRF policies by reusing blocked tabs to export or inspect content that should remain protected. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mag 2026
VulnerabilitàAlta
CVE-2026-39229 - Bolt CMS SQL Injection

CVE ID :CVE-2026-39229 Published : May 29, 2026, 4:16 p.m. | 16 minutes ago Description :Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mag 2026
VulnerabilitàAlta
CVE-2026-36324 - SourceCodester Doctor Appointment System Cross Site Scripting Vulnerability

CVE ID :CVE-2026-36324 Published : May 29, 2026, 4:16 p.m. | 16 minutes ago Description :SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mag 2026
VulnerabilitàAlta
CVE-2026-39276 - Emlog Pro PHP Remote Code Execution (RCE)

CVE ID :CVE-2026-39276 Published : May 29, 2026, 4:16 p.m. | 16 minutes ago Description :The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mag 2026
VulnerabilitàAlta
CVE-2026-32905 (CVSS 8.3)

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices with operator/node capabilities, granting persistent credentials until manual removal.

NVD (NIST)29 mag 2026
VulnerabilitàAlta
CVE-2026-32906 - OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate

CVE ID :CVE-2026-32906 Published : May 29, 2026, 4:16 p.m. | 16 minutes ago Description :OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permissions can bypass intended approval splits to approve plugin actions outside operator configuration. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mag 2026
VulnerabilitàAlta
CVE-2026-33384 - Session Fixation in QuickCMS

CVE ID :CVE-2026-33384 Published : May 29, 2026, 4:16 p.m. | 16 minutes ago Description :QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mag 2026

Pagina 1201 di 2793

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.