Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35415 risultati

VulnerabilitàAlta
CVE-2026-6898 - WishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX action

CVE ID :CVE-2026-6898 Published : May 23, 2026, 4:27 a.m. | 14 hours, 4 minutes ago Description :The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the REST API Secret Key, which can be used to create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mag 2026
News
Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing

Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing Anthropic has revealed the staggering initial results of Project Glasswing, a collaborative cybersecurity initiative designed to secure critical infrastructure using advanced AI before malicious actor ... Read more Published Date: May 23, 2026 (3 days, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5194

CVEfeed Newsroom23 mag 2026
News
Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations

Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations Hackers are using telecom networks and hosting providers across the Middle East as a foundation for massive command-and-control operations, turning trusted infrastructure into a launchpad for cyberatt ... Read more Published Date: May 22, 2026 (3 days, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-11953

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-41149 - Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection

CVE ID :CVE-2026-41149 Published : May 22, 2026, 10:34 p.m. | 19 hours, 57 minutes ago Description :Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If developers are unable to immediately upgrade, they can work around this issue by setting "securityLevel": "sandbox", which prevents the issue by rendering the mermaid diagram in a sandboxed . Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access

Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access Russian state-sponsored threat groups significantly stepped up their cyber operations in 2025, using a range of methods to break into targeted systems. From exploiting remote desktop tools and virtual ... Read more Published Date: May 22, 2026 (3 days, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-49844 CVE-2025-54315 CVE-2025-49090 CVE-2025-20362 CVE-2025-20333 CVE-2025-43300 CVE-2025-8088 CVE-2025-48700 CVE-2025-6218 CVE-2025-49113 CVE-2025-24472 CVE-2025-0411 CVE-2024-55591 CVE-2024-38213 CVE-2024-42009 CVE-2024-37383 CVE-2024-21762 CVE-2017-11882 CVE-2017-0199

CVEfeed Newsroom22 mag 2026
News
Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks

Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks A widely-used JavaScript templating library called art-template has been weaponized to deliver a sophisticated iOS browser exploit kit through a supply chain attack. The backdoored package silently dr ... Read more Published Date: May 22, 2026 (3 days, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-23222

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-23663 - Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability

CVE ID :CVE-2026-23663 Published : May 22, 2026, 10:04 p.m. | 20 hours, 27 minutes ago Description :None Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-42901 - Microsoft Entra ID Elevation of Privilege Vulnerability

CVE ID :CVE-2026-42901 Published : May 22, 2026, 10:04 p.m. | 20 hours, 27 minutes ago Description :None Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-41104 - Microsoft Planetary Computer Pro Information Disclosure Vulnerability

CVE ID :CVE-2026-41104 Published : May 22, 2026, 10:04 p.m. | 20 hours, 27 minutes ago Description :None Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-45659 - Microsoft SharePoint Remote Code Execution Vulnerability

CVE ID :CVE-2026-45659 Published : May 22, 2026, 10:04 p.m. | 20 hours, 27 minutes ago Description :None Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-41148 - Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection

CVE ID :CVE-2026-41148 Published : May 22, 2026, 10:03 p.m. | 16 hours, 27 minutes ago Description :Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through addStyleClass() into createCssStyles() and is assigned to style.innerHTML, so a closing brace (}) in the value terminates the generated CSS selector and turns everything after it into a new CSS rule on the page. This enables page defacement, user tracking via url() callbacks, and DOM attribute exfiltration. This issue has been fixed in versions 10.9.6 and 11.15.0. If developers are unable to immediately upgrade, they can work around this issue by setting "securityLevel": "sandbox", which prevents the issue by rendering the mermaid diagram in a sandboxed . Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-33843 - Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability

CVE ID :CVE-2026-33843 Published : May 22, 2026, 10:03 p.m. | 16 hours, 28 minutes ago Description :None Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026

Pagina 1456 di 2952

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.