Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33693 risultati

VulnerabilitàAlta
CVE-2026-17044 - WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid

CVE ID :CVE-2026-17044 Published : Aug. 9, 2026, 6:18 a.m. | 6 hours, 9 minutes ago Description :The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-17014 - WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips

CVE ID :CVE-2026-17014 Published : Aug. 9, 2026, 6:18 a.m. | 4 hours, 9 minutes ago Description :The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-18032 - WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass

CVE ID :CVE-2026-18032 Published : Aug. 9, 2026, 6:18 a.m. | 6 hours, 9 minutes ago Description :The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to, including user password hashes where that table is the users table. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-16992 - Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication

CVE ID :CVE-2026-16992 Published : Aug. 9, 2026, 6:18 a.m. | 4 hours, 9 minutes ago Description :The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-16965 - Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status

CVE ID :CVE-2026-16965 Published : Aug. 9, 2026, 6:17 a.m. | 2 hours, 10 minutes ago Description :The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19337 - adenot mcp-google-search read_webpage index.ts server-side request forgery

CVE ID :CVE-2026-19337 Published : Aug. 9, 2026, 6:20 a.m. | 10 hours, 8 minutes ago Description :A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called f071d491b685011ca04e8ab8d586fc65f86bcee1. It is advisable to implement a patch to correct this issue. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-16957 - Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure

CVE ID :CVE-2026-16957 Published : Aug. 9, 2026, 6:17 a.m. | 2 hours, 10 minutes ago Description :The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19336 - Pimzino spec-workflow-mcp approvals.ts ApprovalStorage.createApproval path traversal

CVE ID :CVE-2026-19336 Published : Aug. 9, 2026, 6:19 a.m. | 10 hours, 8 minutes ago Description :A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19333 - NightTrek Supabase-MCP generate_types command injection

CVE ID :CVE-2026-19333 Published : Aug. 9, 2026, 5:16 a.m. | 1 hour, 10 minutes ago Description :A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19332 - NellyW8 MCP4EDA run_openlane/view_waveform command injection

CVE ID :CVE-2026-19332 Published : Aug. 9, 2026, 5:16 a.m. | 1 hour, 10 minutes ago Description :A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19334 - NightTrek Ollama-mcp index.ts command injection

CVE ID :CVE-2026-19334 Published : Aug. 9, 2026, 5:16 a.m. | 1 hour, 10 minutes ago Description :A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injection. The attack can only be executed locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026
VulnerabilitàAlta
CVE-2026-19331 - bazylhorsey obsidian-mcp-server CanvasService.ts writeCanvas path traversal

CVE ID :CVE-2026-19331 Published : Aug. 9, 2026, 5:16 a.m. | 1 hour, 10 minutes ago Description :A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approached locally. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 ago 2026

Pagina 146 di 2808

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.