Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35703 risultati

VulnerabilitàAlta
CVE-2026-7798 - FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter

CVE ID :CVE-2026-7798 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.9.87 via the 'SubscribeURL' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Exploitation requires that the SES bounce handling key ('_fc_bounce_key') has never been stored (i.e., the site is in its default/unconfigured state with respect to SES bounce handling) as visiting the bounce configuration page auto-generates and stores a random key that causes the authentication check to evaluate correctly and reject unauthenticated requests. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8679 - AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference to 'audioigniter_playlist_id' Parameter

CVE ID :CVE-2026-8679 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controlled playlist ID via the audioigniter_playlist_id query var or the /audioigniter/playlist/{id}/ rewrite rule and returning playlist track data without performing any authentication, capability, or post_status check — only the post_type is validated. This makes it possible for unauthenticated attackers to view track metadata (titles, artists, audio URLs, buy links, download URLs, and cover images) of any playlist on the site, including those in draft, private, pending, or trash status. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-8381 - Broken Access Control in TeamViewer DEX Platform (On Premises)

CVE ID :CVE-2026-8381 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an authenticated user with low privileges to perform actions and access resources intended only for higher‑privileged roles. An attacker with low‑privileged credentials may exploit this to gain unauthorized access to administrative or sensitive functionality. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-7636 - Slider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclosure via REST API Endpoint

CVE ID :CVE-2026-7636 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract draft slider metadata including unpublished media URLs, captions, and slider configuration authored by administrators or editors. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-7615 - Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via 'wl' Parameter

CVE ID :CVE-2026-7615 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on the save_widget_context_settings function. This makes it possible for unauthenticated attackers to modify widget visibility context settings stored in the WordPress options table via a forged POST request to /wp-admin/widgets.php via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-25608 - Lack of traffic encryption in STER

CVE ID :CVE-2026-25608 Published : May 22, 2026, 10:16 a.m. | 4 hours, 3 minutes ago Description :STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5. Severity: 2.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-25607 - Weak password encoding in STER

CVE ID :CVE-2026-25607 Published : May 22, 2026, 10:16 a.m. | 4 hours, 3 minutes ago Description :Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded. This issue was fixed in version 9.5. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-25606 - SQL Injection in STER

CVE ID :CVE-2026-25606 Published : May 22, 2026, 10:16 a.m. | 4 hours, 3 minutes ago Description :A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for SQL Injection attacks. It allows an authenticated attacker to view sensitive data such as data belonging to other users, or any other data that the application itself is able to access This issue was fixed in version 9.5. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
Microsoft Patches Actively Exploited Defender Vulnerabilities Affecting Enterprise Systems

Microsoft Patches Actively Exploited Defender Vulnerabilities Affecting Enterprise Systems Microsoft has confirmed active exploitation of two security vulnerabilities in its security ecosystem, identified as CVE-2026-41091 and CVE-2026-45498, both evaluated under the CVSS scoring system. Th ... Read more Published Date: May 22, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20223 CVE-2026-45584 CVE-2026-45498 CVE-2026-41091 CVE-2026-45829 CVE-2026-5140 CVE-2026-33825 CVE-2010-0806 CVE-2010-0249 CVE-2009-3459 CVE-2009-1537 CVE-2008-4250

CVEfeed Newsroom22 mag 2026
News
Microsoft publiceert script als tijdelijke fix voor Windows BitLocker-lek

Microsoft publiceert script als tijdelijke fix voor Windows BitLocker-lek Microsoft heeft een script gepubliceerd dat als een tijdelijke oplossing moet dienen voor een kwetsbaarheid in Windows Bitlocker, waardoor een aanvaller met fysieke toegang tot een systeem de versleut ... Read more Published Date: May 22, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45585

CVEfeed Newsroom22 mag 2026
News
Nieuw Linux-lek laat lokale aanvaller SSH-keys stelen en code als root uitvoeren

Nieuw Linux-lek laat lokale aanvaller SSH-keys stelen en code als root uitvoeren Een nieuwe Linux-kwetsbaarheid maakt het mogelijk voor lokale aanvallers om onder andere SSH-keys te stelen en code als root uit te voeren. Updates en mitigaties zijn beschikbaar en beheerders worden ... Read more Published Date: May 22, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-46333

CVEfeed Newsroom22 mag 2026
News
Cisco Secure Workload Flaw CVE-2026-20223 Gets Maximum CVSS 10 Rating

Cisco Secure Workload Flaw CVE-2026-20223 Gets Maximum CVSS 10 Rating Cisco has released security updates to fix a critical vulnerability, tracked as CVE-2026-20223, affecting its Cisco Secure Workload platform. The flaw, which received the maximum CVSS score of 10.0, c ... Read more Published Date: May 22, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20223 CVE-2026-5140

CVEfeed Newsroom22 mag 2026

Pagina 1490 di 2976

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.