Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35703 risultati

VulnerabilitàAlta
CVE-2026-4635 - Persistent notification timing attack causing server denial of service

CVE ID :CVE-2026-4635 Published : May 22, 2026, 10:28 a.m. | 3 hours, 50 minutes ago Description :Mattermost versions 11.6.x Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-3473 - Improper file ownership validation in the Boards API allows unauthorised file access

CVE ID :CVE-2026-3473 Published : May 22, 2026, 10:27 a.m. | 3 hours, 52 minutes ago Description :Mattermost versions 11.6.x Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-4646 - Insufficient input validation in GitHub plugin API causes denial of service

CVE ID :CVE-2026-4646 Published : May 22, 2026, 10:25 a.m. | 3 hours, 54 minutes ago Description :Mattermost versions 11.6.x Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-3636 - Sanitize team member data returned by API

CVE ID :CVE-2026-3636 Published : May 22, 2026, 10:23 a.m. | 3 hours, 56 minutes ago Description :Mattermost versions 11.6.x Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-5740 - Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server

CVE ID :CVE-2026-5740 Published : May 22, 2026, 10:22 a.m. | 3 hours, 57 minutes ago Description :Mattermost versions 11.6.x Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-5308 - Missing request body size limits on Zoom plugin HTTP endpoints

CVE ID :CVE-2026-5308 Published : May 22, 2026, 10:20 a.m. | 3 hours, 59 minutes ago Description :Mattermost versions 11.6.x Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-5755 - Denial of service via crafted TIFF file upload

CVE ID :CVE-2026-5755 Published : May 22, 2026, 10:18 a.m. | 4 hours ago Description :Mattermost versions 11.6.x Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data

Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data Splunk has released security updates addressing multiple vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) condition ... Read more Published Date: May 22, 2026 (2 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20240 CVE-2026-20239 CVE-2026-20238

CVEfeed Newsroom22 mag 2026
News
CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks

CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations ... Read more Published Date: May 22, 2026 (2 days, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34926

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-8684 - MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action

CVE ID :CVE-2026-8684 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite or delete the internal notes (_mphb_booking_internal_notes) of any booking by supplying an arbitrary booking ID. The nonce for this action is output in the HTML source of every public page through wp_localize_script (MPHB._data.nonces), so any unauthenticated visitor can obtain a valid nonce and perform the action without any account or prior interaction. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-9011 - Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via ditty_init AJAX Action

CVE ID :CVE-2026-9011 Published : May 22, 2026, 9:16 a.m. | 5 hours, 3 minutes ago Description :The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve the full item content of non-public Dittys — including drafts, pending, scheduled, and disabled entries — by enumerating integer post IDs against the ditty_init AJAX endpoint. Unlike the non-AJAX init() counterpart, init_ajax() does not verify that the requested Ditty has a 'publish' post status before loading and returning its items, allowing content that administrators explicitly withheld from public view to be extracted. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8692 - Vedrixa Forms <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Structure Modification via wefb_save_form_structure AJAX Action

CVE ID :CVE-2026-8692 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the structure of any form — adding, removing, or altering fields — by writing attacker-controlled data to the plugin's FORMS database table. The 'ajax-nonce' nonce used by this handler is injected into the public frontend via wp_localize_script(), so any authenticated user who visits a page containing a form shortcode can obtain it without any elevated access. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026

Pagina 1489 di 2976

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.