Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33667 risultati

VulnerabilitàAlta
CVE-2026-66408 - Ecovacs DEEBOT PRO Root Account Weak Password Vulnerability

CVE ID :CVE-2026-66408 Published : Aug. 10, 2026, 9:17 a.m. | 1 hour, 13 minutes ago Description :The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
News
Kritiek lek in Progress Kemp LoadMaster-loadbalancers actief misbruikt

Kritiek lek in Progress Kemp LoadMaster-loadbalancers actief misbruikt Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in Progress Kemp LoadMaster-loadbalancers, zo waarschuwt het Amerikaanse cyberagentschap CISA. Updates voor het misbruikte beveiligingsl ... Read more Published Date: Aug 10, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-8037 CVE-2026-33691 CVE-2024-1212

CVEfeed Newsroom6g fa
VulnerabilitàAlta
CVE-2026-21063 - Improper export of android application components

CVE ID :CVE-2026-21063 Published : Aug. 10, 2026, 7:40 a.m. | 49 minutes ago Description :Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-21062 - SemClipboardService Authorization Bypass

CVE ID :CVE-2026-21062 Published : Aug. 10, 2026, 7:40 a.m. | 49 minutes ago Description :Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-21061 - Samsung Dialer Improper Input Validation Vulnerability

CVE ID :CVE-2026-21061 Published : Aug. 10, 2026, 7:40 a.m. | 49 minutes ago Description :Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability. Severity: 6.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-21060 - Samsung Contacts Cross-Profile Data Access Vulnerability

CVE ID :CVE-2026-21060 Published : Aug. 10, 2026, 7:39 a.m. | 50 minutes ago Description :Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-21059 - Samsung Contacts Improper Component Export Arbitrary File Deletion Vulnerability

CVE ID :CVE-2026-21059 Published : Aug. 10, 2026, 7:39 a.m. | 50 minutes ago Description :Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-21058 - Samsung Contacts Arbitrary File Deletion Vulnerability

CVE ID :CVE-2026-21058 Published : Aug. 10, 2026, 7:39 a.m. | 50 minutes ago Description :Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-19075 - All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter

CVE ID :CVE-2026-19075 Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 13 minutes ago Description :All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-19077 - Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization

CVE ID :CVE-2026-19077 Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 13 minutes ago Description :The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-19089 - Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload

CVE ID :CVE-2026-19089 Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 13 minutes ago Description :The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-19053 - ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter

CVE ID :CVE-2026-19053 Published : Aug. 10, 2026, 7:16 a.m. | 1 hour, 13 minutes ago Description :The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa

Pagina 135 di 2806

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.