Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35345 risultati

VulnerabilitàAlta
CVE-2026-9532 - Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection

CVE ID :CVE-2026-9532 Published : May 26, 2026, 5 a.m. | 7 hours, 31 minutes ago Description :A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9496 - Pacote Denial of Service (DoS) Vulnerability

CVE ID :CVE-2026-9496 Published : May 26, 2026, 5 a.m. | 7 hours, 31 minutes ago Description :Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9495 - Koa Router Access Control Bypass Vulnerability

CVE ID :CVE-2026-9495 Published : May 26, 2026, 5 a.m. | 7 hours, 32 minutes ago Description :Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attacker could bypass authentication and authorization, evade rate limiting or bypass input sanitization. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9531 - Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection

CVE ID :CVE-2026-9531 Published : May 26, 2026, 4:45 a.m. | 7 hours, 46 minutes ago Description :A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9530 - GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds

CVE ID :CVE-2026-9530 Published : May 26, 2026, 4:30 a.m. | 8 hours, 1 minute ago Description :A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgbmp Utility. Executing a manipulation can lead to out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called 8f03865f37f5d4ffd616fef802acc980be54d300. It is advisable to implement a patch to correct this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9529 - GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference

CVE ID :CVE-2026-9529 Published : May 26, 2026, 4:15 a.m. | 8 hours, 16 minutes ago Description :A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
News
New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems

New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems A critical heap buffer overflow vulnerability has been disclosed in 7-Zip version 26.00, enabling attackers to achieve arbitrary code execution via a vtable hijack by exploiting a defect in the tool’s ... Read more Published Date: May 26, 2026 (1 day, 12 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom26 mag 2026
VulnerabilitàAlta
CVE-2026-9528 - itsourcecode Electronic Judging System delete_judge.php sql injection

CVE ID :CVE-2026-9528 Published : May 26, 2026, 4 a.m. | 8 hours, 31 minutes ago Description :A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9527 - itsourcecode Electronic Judging System judges.php cross site scripting

CVE ID :CVE-2026-9527 Published : May 26, 2026, 3:45 a.m. | 8 hours, 46 minutes ago Description :A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument fname causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9526 - itsourcecode Electronic Judging System edit_team.php sql injection

CVE ID :CVE-2026-9526 Published : May 26, 2026, 3:30 a.m. | 9 hours, 1 minute ago Description :A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9525 - itsourcecode Electronic Judging System edit_judge.php sql injection

CVE ID :CVE-2026-9525 Published : May 26, 2026, 3 a.m. | 5 hours, 31 minutes ago Description :A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument judge_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026
VulnerabilitàAlta
CVE-2026-9524 - xianrendzw EasyReport REST Endpoint execute sql injection

CVE ID :CVE-2026-9524 Published : May 26, 2026, 2:45 a.m. | 5 hours, 46 minutes ago Description :A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mag 2026

Pagina 1424 di 2946

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.