Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33693 risultati

VulnerabilitàAlta
CVE-2026-19355 - MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection

CVE ID :CVE-2026-19355 Published : Aug. 9, 2026, 2:17 p.m. | 8 hours, 12 minutes ago Description :A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19356 - MingSoft MCMS ms-mdiy list information disclosure

CVE ID :CVE-2026-19356 Published : Aug. 9, 2026, 2:17 p.m. | 8 hours, 12 minutes ago Description :A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19353 - DedeCMS Installation Wizard index.php _4_Setup file inclusion

CVE ID :CVE-2026-19353 Published : Aug. 9, 2026, 1:16 p.m. | 9 hours, 12 minutes ago Description :A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19352 - mifi lossless-cut Built-in HTTP API Service httpServer.ts server-side request forgery

CVE ID :CVE-2026-19352 Published : Aug. 9, 2026, 1:16 p.m. | 9 hours, 12 minutes ago Description :A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19354 - lock-upme OPMS IN Clause message.go sql injection

CVE ID :CVE-2026-19354 Published : Aug. 9, 2026, 2:17 p.m. | 8 hours, 12 minutes ago Description :A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql injection. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19351 (CVSS 7.3)

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.

NVD (NIST)09 ago 2026
VulnerabilitàAlta
CVE-2026-19351 - dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection

CVE ID :CVE-2026-19351 Published : Aug. 9, 2026, 12:16 p.m. | 10 hours, 13 minutes ago Description :A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàCritica
CVE-2026-19348 (CVSS 9.8)

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)09 ago 2026
VulnerabilitàAlta
CVE-2026-19350 - Dolibarr ERP TakePOS invoice.php fail authorization

CVE ID :CVE-2026-19350 Published : Aug. 9, 2026, 11:16 a.m. | 11 hours, 12 minutes ago Description :A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19348 - Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection

CVE ID :CVE-2026-19348 Published : Aug. 9, 2026, 11:16 a.m. | 11 hours, 12 minutes ago Description :A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19347 - itsourcecode Hospital Management System viewdoctor.php sql injection

CVE ID :CVE-2026-19347 Published : Aug. 9, 2026, 11:16 a.m. | 9 hours, 12 minutes ago Description :A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19346 (CVSS 8.8)

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

NVD (NIST)09 ago 2026

Pagina 143 di 2808

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.