News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
35433 risultati
CVE ID :CVE-2026-9294 Published : May 23, 2026, 7:30 a.m. | 11 hours, 1 minute ago Description :A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based o ... Read more Published Date: May 23, 2026 (3 days, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9082 CVE-2026-42897 CVE-2026-41940
CVE ID :CVE-2026-6419 Published : May 23, 2026, 4:27 a.m. | 14 hours, 4 minutes ago Description :The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to supply an arbitrary admin screen identifier via the data[url] parameter, causing the plugin to load and execute the administrative API configuration template without authorization. The rendered HTML, which contains the plugin's plaintext REST API Secret Key, is returned directly to the attacker in the AJAX JSON response. An attacker who obtains this key can authenticate to the WishList Member API, create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6897 Published : May 23, 2026, 4:27 a.m. | 14 hours, 4 minutes ago Description :The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin options, includes the REST API Secret Key, which can be used to create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-9284 Published : May 23, 2026, 4:27 a.m. | 14 hours, 4 minutes ago Description :The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it. The `ppc-get-order` endpoint returns full PayPal order details for any PayPal order ID without binding to the requester's session. This makes it possible for unauthenticated attackers to chain these endpoints to manipulate other customers' order payment flows and exfiltrate sensitive order details (payer information, shipping data) by creating a PayPal order for a victim's WC order and then retrieving the PayPal order data. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6895 Published : May 23, 2026, 4:27 a.m. | 14 hours, 4 minutes ago Description :The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can authenticate to the WishList Member API, create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6898 Published : May 23, 2026, 4:27 a.m. | 14 hours, 4 minutes ago Description :The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the REST API Secret Key, which can be used to create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing Anthropic has revealed the staggering initial results of Project Glasswing, a collaborative cybersecurity initiative designed to secure critical infrastructure using advanced AI before malicious actor ... Read more Published Date: May 23, 2026 (3 days, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5194
Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations Hackers are using telecom networks and hosting providers across the Middle East as a foundation for massive command-and-control operations, turning trusted infrastructure into a launchpad for cyberatt ... Read more Published Date: May 22, 2026 (3 days, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-11953
CVE ID :CVE-2026-41149 Published : May 22, 2026, 10:34 p.m. | 19 hours, 57 minutes ago Description :Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If developers are unable to immediately upgrade, they can work around this issue by setting "securityLevel": "sandbox", which prevents the issue by rendering the mermaid diagram in a sandboxed . Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access Russian state-sponsored threat groups significantly stepped up their cyber operations in 2025, using a range of methods to break into targeted systems. From exploiting remote desktop tools and virtual ... Read more Published Date: May 22, 2026 (3 days, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-49844 CVE-2025-54315 CVE-2025-49090 CVE-2025-20362 CVE-2025-20333 CVE-2025-43300 CVE-2025-8088 CVE-2025-48700 CVE-2025-6218 CVE-2025-49113 CVE-2025-24472 CVE-2025-0411 CVE-2024-55591 CVE-2024-38213 CVE-2024-42009 CVE-2024-37383 CVE-2024-21762 CVE-2017-11882 CVE-2017-0199
Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks A widely-used JavaScript templating library called art-template has been weaponized to deliver a sophisticated iOS browser exploit kit through a supply chain attack. The backdoored package silently dr ... Read more Published Date: May 22, 2026 (3 days, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-23222
Pagina 1457 di 2953