Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35352 risultati

VulnerabilitàAlta
CVE-2026-48850 - PuTTY RSA KEX Double Free Vulnerability

CVE ID :CVE-2026-48850 Published : May 25, 2026, 8:13 p.m. | 2 hours, 18 minutes ago Description :PuTTY 0.72 before 0.84 has a double free in RSA KEX. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9498 - Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine

CVE ID :CVE-2026-9498 Published : May 25, 2026, 8 p.m. | 31 minutes ago Description :A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument DefMsgTemplate.content leads to improper neutralization of special elements used in a template engine. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9497 - changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject deserialization

CVE ID :CVE-2026-9497 Published : May 25, 2026, 7:45 p.m. | 46 minutes ago Description :A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-48849 - Roundcube Webmail Stored XSS/HTML/CSS Injection

CVE ID :CVE-2026-48849 Published : May 25, 2026, 7:30 p.m. | 1 hour, 1 minute ago Description :In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9486 - SourceCodester Student Grades Management System cross-site request forgery

CVE ID :CVE-2026-9486 Published : May 25, 2026, 7:30 p.m. | 1 hour, 1 minute ago Description :A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-48848 - Roundcube Webmail CSS Injection Vulnerability

CVE ID :CVE-2026-48848 Published : May 25, 2026, 7:27 p.m. | 1 hour, 4 minutes ago Description :Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-24546 - WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability

CVE ID :CVE-2026-24546 Published : May 25, 2026, 7:26 p.m. | 1 hour, 5 minutes ago Description :Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-48847 - Roundcube Webmail Redis/Memcache File Deletion Vulnerability

CVE ID :CVE-2026-48847 Published : May 25, 2026, 7:23 p.m. | 1 hour, 8 minutes ago Description :Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-48846 - Roundcube Webmail CSS Injection Vulnerability

CVE ID :CVE-2026-48846 Published : May 25, 2026, 7:21 p.m. | 1 hour, 10 minutes ago Description :In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-48845 - Roundcube Webmail Local/Private Image Disclosure Vulnerability

CVE ID :CVE-2026-48845 Published : May 25, 2026, 7:18 p.m. | 1 hour, 13 minutes ago Description :In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-9485 - SourceCodester Student Grades Management System students.php cross site scripting

CVE ID :CVE-2026-9485 Published : May 25, 2026, 7:15 p.m. | 1 hour, 16 minutes ago Description :A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2026-48844 - Roundcube Webmail LDAP Code Injection Vulnerability

CVE ID :CVE-2026-48844 Published : May 25, 2026, 7:14 p.m. | 1 hour, 17 minutes ago Description :Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.) Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026

Pagina 1430 di 2946

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.