Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35356 risultati

VulnerabilitàAlta
CVE-2018-25364 - Twitter-Clone 1 SQL Injection via search.php

CVE ID :CVE-2018-25364 Published : May 25, 2026, 2:15 p.m. | 16 minutes ago Description :Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the name parameter. Attackers can submit crafted payloads to the search.php endpoint to extract database information including usernames, credentials, and system data using error-based and union-based SQL injection techniques. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2018-25363 - Twitter-Clone 1 Cross-Site Request Forgery via tweetdel.php

CVE ID :CVE-2018-25363 Published : May 25, 2026, 2:15 p.m. | 16 minutes ago Description :Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms targeting tweetdel.php with tweet IDs and automatically submit them to delete arbitrary posts from authenticated user sessions. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2018-25362 - Twitter-Clone 1 SQL Injection via follow.php

CVE ID :CVE-2018-25362 Published : May 25, 2026, 2:15 p.m. | 16 minutes ago Description :Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information including usernames, passwords, and database credentials. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2018-25361 - Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection

CVE ID :CVE-2018-25361 Published : May 25, 2026, 2:15 p.m. | 16 minutes ago Description :Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and access all stored data, chats, images, and files without knowing the original passcode. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2018-25360 - AgataSoft Auto PingMaster 1.5 Buffer Overflow SEH

CVE ID :CVE-2018-25360 Published : May 25, 2026, 2:15 p.m. | 16 minutes ago Description :AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious ping.txt file with shellcode and jump instructions that overwrite the SEH handler pointer to achieve code execution when the file contents are pasted into the application. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
VulnerabilitàAlta
CVE-2018-25359 - Splinterware System Scheduler Pro 5.12 Privilege Escalation

CVE ID :CVE-2018-25359 Published : May 25, 2026, 2:15 p.m. | 16 minutes ago Description :Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
News
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent th ... Read more Published Date: May 25, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom25 mag 2026
VulnerabilitàAlta
CVE-2026-9078 - Firefox iOS RTL Domain Rendering Issue in Link Preview

CVE ID :CVE-2026-9078 Published : May 25, 2026, 2:05 p.m. | 26 minutes ago Description :Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026
News
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. Knowled ... Read more Published Date: May 25, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5426

CVEfeed Newsroom25 mag 2026
News
Micropatches released for Windows Shell Link Processing Spoofing Vulnerability (CVE-2026-25185)

Micropatches released for Windows Shell Link Processing Spoofing Vulnerability (CVE-2026-25185) March 2026 Windows Updates brought a patch for CVE-2026-25185, a flaw in Windows Explorer's processing of .LNK files that allowed an attacker to force user's computer to authenticate to a malicious se ... Read more Published Date: May 25, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-25185

CVEfeed Newsroom25 mag 2026
News
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity ... Read more Published Date: May 25, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45585 CVE-2026-42945 CVE-2026-31635 CVE-2026-26980

CVEfeed Newsroom25 mag 2026
VulnerabilitàAlta
CVE-2026-9456 - Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection

CVE ID :CVE-2026-9456 Published : May 25, 2026, noon | 31 minutes ago Description :A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enabled results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mag 2026

Pagina 1435 di 2947

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.