News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
33667 risultati
CVE ID :CVE-2026-66408 Published : Aug. 10, 2026, 9:17 a.m. | 1 hour, 13 minutes ago Description :The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Kritiek lek in Progress Kemp LoadMaster-loadbalancers actief misbruikt Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in Progress Kemp LoadMaster-loadbalancers, zo waarschuwt het Amerikaanse cyberagentschap CISA. Updates voor het misbruikte beveiligingsl ... Read more Published Date: Aug 10, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-8037 CVE-2026-33691 CVE-2024-1212
CVE ID :CVE-2026-21063 Published : Aug. 10, 2026, 7:40 a.m. | 49 minutes ago Description :Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21062 Published : Aug. 10, 2026, 7:40 a.m. | 49 minutes ago Description :Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21061 Published : Aug. 10, 2026, 7:40 a.m. | 49 minutes ago Description :Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability. Severity: 6.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21060 Published : Aug. 10, 2026, 7:39 a.m. | 50 minutes ago Description :Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21059 Published : Aug. 10, 2026, 7:39 a.m. | 50 minutes ago Description :Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-21058 Published : Aug. 10, 2026, 7:39 a.m. | 50 minutes ago Description :Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19075 Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 13 minutes ago Description :All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19077 Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 13 minutes ago Description :The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19089 Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 13 minutes ago Description :The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19053 Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 13 minutes ago Description :The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 135 di 2806