Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35395 risultati

VulnerabilitàAlta
CVE-2018-25343 - Smartshop 1 Cross-Site Request Forgery via editprofile.php

CVE ID :CVE-2018-25343 Published : May 23, 2026, 6:30 p.m. | 8 hours, 1 minute ago Description :Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting editprofile.php with hidden fields for email and password parameters that execute automatically when visited by an authenticated admin user. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2018-25342 - Smartshop 1 SQL Injection via search.php

CVE ID :CVE-2018-25342 Published : May 23, 2026, 6:30 p.m. | 8 hours, 1 minute ago Description :Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'searched' parameter in search.php. Attackers can send GET requests with malicious SQL payloads like SLEEP commands to extract sensitive database information including product details and system data. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2018-25341 - Smartshop 1 SQL Injection via product.php id Parameter

CVE ID :CVE-2018-25341 Published : May 23, 2026, 6:30 p.m. | 8 hours, 1 minute ago Description :Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to product.php with union-based SQL injection payloads in the id parameter to extract sensitive database information including usernames and database names. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2018-25340 - Smartshop 1 SQL Injection via category.php

CVE ID :CVE-2018-25340 Published : May 23, 2026, 6:30 p.m. | 8 hours, 1 minute ago Description :Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to category.php with UNION-based SQL injection payloads in the id parameter to extract sensitive database information including usernames and other data. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9306 - QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization

CVE ID :CVE-2026-9306 Published : May 23, 2026, 3 p.m. | 9 hours, 31 minutes ago Description :A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9305 - QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection

CVE ID :CVE-2026-9305 Published : May 23, 2026, 2:30 p.m. | 10 hours, 1 minute ago Description :A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9304 - calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery

CVE ID :CVE-2026-9304 Published : May 23, 2026, 1:45 p.m. | 10 hours, 46 minutes ago Description :A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9303 - calcom cal.diy cross-site request forgery

CVE ID :CVE-2026-9303 Published : May 23, 2026, 1:30 p.m. | 9 hours, 1 minute ago Description :A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9302 - 546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection

CVE ID :CVE-2026-9302 Published : May 23, 2026, 1:15 p.m. | 9 hours, 16 minutes ago Description :A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/command/VpsTest.php of the component VpsTest Console. Executing a manipulation of the argument vf can lead to code injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
VulnerabilitàAlta
CVE-2026-9301 - omec-project amf NGReset Message memory corruption

CVE ID :CVE-2026-9301 Published : May 23, 2026, 1 p.m. | 7 hours, 31 minutes ago Description :A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. It is recommended to apply a patch to fix this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
News
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the ... Read more Published Date: May 23, 2026 (3 days, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897 CVE-2026-41940 CVE-2026-5194

CVEfeed Newsroom23 mag 2026
News
Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now!

Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now! A newly disclosed flaw in one of the world’s most widely deployed web servers is forcing administrators into another emergency patch cycle. Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolsl ... Read more Published Date: May 23, 2026 (3 days, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9256 CVE-2026-42945

CVEfeed Newsroom23 mag 2026

Pagina 1452 di 2950

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.