Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35763 risultati

VulnerabilitàAlta
CVE-2026-3481 - WP Blockade <= 0.9.14 - Reflected Cross-Site Scripting via 'shortcode' Parameter

CVE ID :CVE-2026-3481 Published : May 22, 2026, 5:16 a.m. | 5 hours, 3 minutes ago Description :The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input sanitization and output escaping in the render_shortcode_preview() function. The function receives user input from $_GET['shortcode'], passes it through stripslashes() without any sanitization, and then outputs it directly via echo do_shortcode($shortcode) on line 393. When the input is not a valid WordPress shortcode (e.g., an HTML tag with JavaScript event handlers), do_shortcode() returns it unchanged, and it is reflected into the page without escaping. The endpoint is registered via admin_post_ (not admin_post_nopriv_), meaning it requires the user to be logged in with at minimum a Subscriber-level account. There is no nonce verification or additional capability check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute if they can successfully trick a user into performing an action such as clicking a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-2518 - FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation and Activation

CVE ID :CVE-2026-2518 Published : May 22, 2026, 5:16 a.m. | 5 hours, 3 minutes ago Description :The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing capability checks on the 'ultp_install_callback' and 'ultp_activate_callback' functions in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the PostX plugin. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
News
CVE-2026-20223 — Cisco Secure Workload Authentication Bypass

CVE-2026-20223 — Cisco Secure Workload Authentication Bypass May 22, 2026CVE-2026-20223 is assigned a maximum CVSS base score of 10.0. The vulnerability allows remote, completely unauthenticated threat actors to cross isolated tenant boundaries and gain full co ... Read more Published Date: May 22, 2026 (19 hours, 27 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-20223

CVEfeed Newsroom22 mag 2026
VulnerabilitàAlta
CVE-2026-4834 (CVSS 7.5)

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)22 mag 2026
VulnerabilitàAlta
CVE-2026-4834 - WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter

CVE ID :CVE-2026-4834 Published : May 22, 2026, 4:16 a.m. | 6 hours, 3 minutes ago Description :The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-9054 - Invalid IP packets cause a kernel panic

CVE ID :CVE-2026-9054 Published : May 22, 2026, 4:16 a.m. | 6 hours, 3 minutes ago Description :An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-9053 - Apache HTML File Upload Default Path Disclosure

CVE ID :CVE-2026-9053 Published : May 22, 2026, 4:16 a.m. | 6 hours, 3 minutes ago Description :Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-39834 - Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

CVE ID :CVE-2026-39834 Published : May 22, 2026, 4:16 a.m. | 4 hours, 3 minutes ago Description :When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-42508 - Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

CVE ID :CVE-2026-42508 Published : May 22, 2026, 4:16 a.m. | 4 hours, 3 minutes ago Description :Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-39829 - Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

CVE ID :CVE-2026-39829 Published : May 22, 2026, 4:16 a.m. | 4 hours, 3 minutes ago Description :The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-46598 - Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

CVE ID :CVE-2026-46598 Published : May 22, 2026, 4:16 a.m. | 6 hours, 3 minutes ago Description :For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026
VulnerabilitàAlta
CVE-2026-46595 - Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh

CVE ID :CVE-2026-46595 Published : May 22, 2026, 4:16 a.m. | 4 hours, 3 minutes ago Description :Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mag 2026

Pagina 1497 di 2981

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.