News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
35703 risultati
CVE ID :CVE-2026-7798 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.9.87 via the 'SubscribeURL' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Exploitation requires that the SES bounce handling key ('_fc_bounce_key') has never been stored (i.e., the site is in its default/unconfigured state with respect to SES bounce handling) as visiting the bounce configuration page auto-generates and stores a random key that causes the authentication check to evaluate correctly and reject unauthenticated requests. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8679 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controlled playlist ID via the audioigniter_playlist_id query var or the /audioigniter/playlist/{id}/ rewrite rule and returning playlist track data without performing any authentication, capability, or post_status check — only the post_type is validated. This makes it possible for unauthenticated attackers to view track metadata (titles, artists, audio URLs, buy links, download URLs, and cover images) of any playlist on the site, including those in draft, private, pending, or trash status. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8381 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an authenticated user with low privileges to perform actions and access resources intended only for higher‑privileged roles. An attacker with low‑privileged credentials may exploit this to gain unauthorized access to administrative or sensitive functionality. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7636 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract draft slider metadata including unpublished media URLs, captions, and slider configuration authored by administrators or editors. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7615 Published : May 22, 2026, 9:16 a.m. | 3 hours, 3 minutes ago Description :The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on the save_widget_context_settings function. This makes it possible for unauthenticated attackers to modify widget visibility context settings stored in the WordPress options table via a forged POST request to /wp-admin/widgets.php via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-25608 Published : May 22, 2026, 10:16 a.m. | 4 hours, 3 minutes ago Description :STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5. Severity: 2.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-25607 Published : May 22, 2026, 10:16 a.m. | 4 hours, 3 minutes ago Description :Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded. This issue was fixed in version 9.5. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-25606 Published : May 22, 2026, 10:16 a.m. | 4 hours, 3 minutes ago Description :A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for SQL Injection attacks. It allows an authenticated attacker to view sensitive data such as data belonging to other users, or any other data that the application itself is able to access This issue was fixed in version 9.5. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Microsoft Patches Actively Exploited Defender Vulnerabilities Affecting Enterprise Systems Microsoft has confirmed active exploitation of two security vulnerabilities in its security ecosystem, identified as CVE-2026-41091 and CVE-2026-45498, both evaluated under the CVSS scoring system. Th ... Read more Published Date: May 22, 2026 (1 day, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20223 CVE-2026-45584 CVE-2026-45498 CVE-2026-41091 CVE-2026-45829 CVE-2026-5140 CVE-2026-33825 CVE-2010-0806 CVE-2010-0249 CVE-2009-3459 CVE-2009-1537 CVE-2008-4250
Microsoft publiceert script als tijdelijke fix voor Windows BitLocker-lek Microsoft heeft een script gepubliceerd dat als een tijdelijke oplossing moet dienen voor een kwetsbaarheid in Windows Bitlocker, waardoor een aanvaller met fysieke toegang tot een systeem de versleut ... Read more Published Date: May 22, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45585
Nieuw Linux-lek laat lokale aanvaller SSH-keys stelen en code als root uitvoeren Een nieuwe Linux-kwetsbaarheid maakt het mogelijk voor lokale aanvallers om onder andere SSH-keys te stelen en code als root uit te voeren. Updates en mitigaties zijn beschikbaar en beheerders worden ... Read more Published Date: May 22, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-46333
Cisco Secure Workload Flaw CVE-2026-20223 Gets Maximum CVSS 10 Rating Cisco has released security updates to fix a critical vulnerability, tracked as CVE-2026-20223, affecting its Cisco Secure Workload platform. The flaw, which received the maximum CVSS score of 10.0, c ... Read more Published Date: May 22, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20223 CVE-2026-5140
Pagina 1490 di 2976