Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35347 risultati

VulnerabilitàAlta
CVE-2026-24527 - WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.14.0 - Broken Access Control vulnerability

CVE ID :CVE-2026-24527 Published : May 25, 2026, 9:40 p.m. | 2 hours, 51 minutes ago Description :Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2025-62745 - WordPress Team Showcase plugin <= 1.22.28 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2025-62745 Published : May 25, 2026, 9:34 p.m. | 57 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-24586 - WordPress Newses theme <= 2.0.0.77 - Broken Access Control vulnerability

CVE ID :CVE-2026-24586 Published : May 25, 2026, 9:32 p.m. | 59 minutes ago Description :Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Newses: from n/a through 2.0.0.77. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-24592 - WordPress Auto Affiliate Links plugin <= 6.8.8.3 - Broken Access Control vulnerability

CVE ID :CVE-2026-24592 Published : May 25, 2026, 9:31 p.m. | 1 hour ago Description :Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9504 - GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds

CVE ID :CVE-2026-9504 Published : May 25, 2026, 9:15 p.m. | 1 hour, 16 minutes ago Description :A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: be996bf2178a40e98720f18c2414815d244413db. Applying a patch is the recommended action to fix this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-24582 - WordPress FlexTable plugin <= 3.24.0 - Broken Access Control vulnerability

CVE ID :CVE-2026-24582 Published : May 25, 2026, 9:10 p.m. | 1 hour, 21 minutes ago Description :Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexTable: from n/a through 3.24.0. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-24545 - WordPress QR Redirector plugin <= 2.0.3 - Broken Access Control vulnerability

CVE ID :CVE-2026-24545 Published : May 25, 2026, 9:08 p.m. | 1 hour, 23 minutes ago Description :Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-24574 - WordPress Export WP Page to Static HTML/CSS plugin <= 6.0.0 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-24574 Published : May 25, 2026, 9:07 p.m. | 1 hour, 24 minutes ago Description :Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-24597 - WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-24597 Published : May 25, 2026, 9:05 p.m. | 1 hour, 26 minutes ago Description :Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This issue affects Organization chart: from n/a through 1.7.5. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9503 - GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference

CVE ID :CVE-2026-9503 Published : May 25, 2026, 9 p.m. | 1 hour, 31 minutes ago Description :A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 8f03865f37f5d4ffd616fef802acc980be54d300. Upgrading the affected component is advised. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9502 - GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflow

CVE ID :CVE-2026-9502 Published : May 25, 2026, 8:45 p.m. | 1 hour, 46 minutes ago Description :A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is e501cb9926c1e9a07a0d1cc997f3e69e9be801c9. To fix this issue, it is recommended to deploy a patch. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9501 - GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion

CVE ID :CVE-2026-9501 Published : May 25, 2026, 8:30 p.m. | 2 hours, 1 minute ago Description :A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. This patch is called e501cb9926c1e9a07a0d1cc997f3e69e9be801c9. A patch should be applied to remediate this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026

Pagina 1428 di 2946

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.