Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33665 risultati

VulnerabilitàAlta
CVE-2026-59112 - Signature validation vulnerability affecting DigiDoc applications

CVE ID :CVE-2026-59112 Published : Aug. 10, 2026, 2:17 p.m. | 13 minutes ago Description :Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa
VulnerabilitàAlta
CVE-2026-63105 - ReadyEcommerce < 4.5.2 Stored XSS via Chat and Support Ticket Systems

CVE ID :CVE-2026-63105 Published : Aug. 10, 2026, 2:17 p.m. | 13 minutes ago Description :ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML payloads through the chat and support ticket messaging systems by exploiting unsanitized rendering via the v-html directive in Messages.vue, RightChatSidebar.vue, SupportTicketMessages.vue, and SupportTicketDetails.vue. Attackers can submit crafted message content that executes arbitrary JavaScript in the browser of any shop owner or administrator who views the message, enabling session cookie theft and account takeover. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa
VulnerabilitàAlta
CVE-2026-15060 - systemd-machined: unprivileged users can terminate arbitrary processes

CVE ID :CVE-2026-15060 Published : Aug. 10, 2026, 2:17 p.m. | 13 minutes ago Description :When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa
VulnerabilitàAlta
CVE-2026-16742 - systemd-homed: local privilege escalation via missing home-record signature verification on the authenticate path

CVE ID :CVE-2026-16742 Published : Aug. 10, 2026, 2:17 p.m. | 13 minutes ago Description :systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa
VulnerabilitàAlta
CVE-2026-18478 - Stored XSS in Magnolia CMS

CVE ID :CVE-2026-18478 Published : Aug. 10, 2026, 2:17 p.m. | 13 minutes ago Description :Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10 Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa
VulnerabilitàAlta
CVE-2026-18503 - Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()

CVE ID :CVE-2026-18503 Published : Aug. 10, 2026, 2:17 p.m. | 13 minutes ago Description :Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff(). Severity: 2.4 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa
VulnerabilitàAlta
CVE-2026-15059 - systemd-oomd: unprivileged users can terminate arbitrary processes

CVE ID :CVE-2026-15059 Published : Aug. 10, 2026, 2:17 p.m. | 13 minutes ago Description :Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa
News
Microsoft vermoedt dat criminelen ransomware verspreiden via N-Central-lek

Microsoft vermoedt dat criminelen ransomware verspreiden via N-Central-lek Criminelen gebruiken vermoedelijk een beveiligingslek in N-Central van N-Able om organisaties met ransomware te infecteren, zo stelt Microsoft op X. Het gaat om een beveiligingslek aangeduid als CVE-2 ... Read more Published Date: Aug 10, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-18577 CVE-2026-18556

CVEfeed Newsroom5g fa
News
Vulnerability in Magnolia CMS software

Vulnerability in Magnolia CMS software Vulnerability in Magnolia CMS software CVE ID CVE-2026-18478 Publication date 10 August 2026 Vendor Magnolia DXP Product Magnolia CMS Vulnerable versions From 6.3.0 to 6.3.10 Vulnerability type (CWE) ... Read more Published Date: Aug 10, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom5g fa
VulnerabilitàAlta
CVE-2026-72690 - Attendize Attendize - Cross-Tenant Authorization Bypass

CVE ID :CVE-2026-72690 Published : Aug. 10, 2026, 1:20 p.m. | 1 hour, 9 minutes ago Description :An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events via the POST /event/{event_id}/question/create endpoint. The postCreateEventQuestion method loads the target event without the tenant-isolation scope, enabling cross-tenant writes; the injected question cannot be removed by the victim because the victim's account-scoped delete path cannot resolve a question owned by another tenant. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa
VulnerabilitàAlta
CVE-2026-72689 - OpenSignLabs opensignserver - Broken Object Level Authorization

CVE ID :CVE-2026-72689 Published : Aug. 10, 2026, 1:20 p.m. | 1 hour, 9 minutes ago Description :A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the document's IsEnableOTP flag is unset, which is the default configuration. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa
VulnerabilitàAlta
CVE-2026-72692 - OpenSignLabs opensignserver - Missing Authorization

CVE ID :CVE-2026-72692 Published : Aug. 10, 2026, 1:20 p.m. | 1 hour, 9 minutes ago Description :A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The function writes IsDeclined, DeclineReason, and a caller-supplied DeclineBy pointer without verifying the caller's identity, enabling workflow termination and evidentiary record falsification against any accessible document. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE5g fa

Pagina 128 di 2806

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.