Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35791 risultati

VulnerabilitàAlta
CVE-2026-48240 - Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id Parameters

CVE ID :CVE-2026-48240 Published : May 21, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_tick_id POST parameters are concatenated into WHERE clauses of SELECT statements in the statistics rollup queries without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-48239 - Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter

CVE ID :CVE-2026-48239 Published : May 21, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST parameter is concatenated into the WHERE clause of SELECT statements in the incidents summary report without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-48235 - Open ISES Tickets < 3.44.2 SQL Injection in incs/remotes.inc.php via External GPS Tracker Data

CVE ID :CVE-2026-48235 Published : May 21, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/remotes.inc.php where latitude, longitude, callsign, mph, altitude, and timestamp values parsed from external GPS tracking service XML/JSON responses (InstaMapper and Google Latitude integration) are concatenated into UPDATE and INSERT statements without sanitization. An attacker able to compromise or impersonate the remote GPS tracker endpoint can inject SQL to manipulate the responder location, tracks, and assignment tables. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-48236 - Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters

CVE ID :CVE-2026-48236 Published : May 21, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST parameters (ticketsdb, ticketshost, ticketsuser, ticketspassword) are concatenated into mysqli connection arguments and dynamic SQL operating against an attacker-controlled database without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-48237 - Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id Parameters

CVE ID :CVE-2026-48237 Published : May 21, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and frm_resp_id POST parameters are concatenated into WHERE clauses of SELECT/UPDATE statements without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-48232 (CVSS 7.1)

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GET parameter is concatenated into the LIMIT clause of a SELECT statement without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

NVD (NIST)21 mag 2026
VulnerabilitàAlta
CVE-2026-48231 (CVSS 7.1)

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters (tablename, indexname, sortby) are concatenated into table/column identifiers in dynamically constructed SELECT/UPDATE/DELETE statements without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

NVD (NIST)21 mag 2026
VulnerabilitàAlta
CVE-2026-48231 - Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple Parameters

CVE ID :CVE-2026-48231 Published : May 21, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters (tablename, indexname, sortby) are concatenated into table/column identifiers in dynamically constructed SELECT/UPDATE/DELETE statements without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-48232 - Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset Parameter

CVE ID :CVE-2026-48232 Published : May 21, 2026, 6:16 p.m. | 2 hours, 2 minutes ago Description :Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GET parameter is concatenated into the LIMIT clause of a SELECT statement without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
News
Critical Chrome Vulnerabilities Enable Remote Code Execution Attacks – Patch Now!

Critical Chrome Vulnerabilities Enable Remote Code Execution Attacks – Patch Now! Google has released an urgent security update for Chrome, addressing 16 vulnerabilities including two rated Critical that could allow attackers to execute arbitrary code on affected systems. The Stab ... Read more Published Date: May 21, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-9126 CVE-2026-9124 CVE-2026-9123 CVE-2026-9122 CVE-2026-9121 CVE-2026-9120 CVE-2026-9119 CVE-2026-9118 CVE-2026-9117 CVE-2026-9116 CVE-2026-9115 CVE-2026-9114 CVE-2026-9113 CVE-2026-9112 CVE-2026-9111 CVE-2026-9110

CVEfeed Newsroom21 mag 2026
VulnerabilitàAlta
CVE-2026-48213 - Open ISES Tickets < 3.44.2 Reflected XSS via add.php ticket_id Parameter

CVE ID :CVE-2026-48213 Published : May 21, 2026, 5:16 p.m. | 1 hour, 2 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id POST parameter directly into an HTML form input value attribute. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026
VulnerabilitàAlta
CVE-2026-48207 - Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement

CVE ID :CVE-2026-48207 Published : May 21, 2026, 5:16 p.m. | 1 hour, 2 minutes ago Description :Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Python-native mode with strict mode disabled and relies on DeserializationPolicy to restrict unsafe classes, functions, or module attributes. This issue affects Apache Fory: from before 1.0.0. Mitigation: Users of Apache Fory are recommended to upgrade to version 1.0.0 or later, which enforces DeserializationPolicy validation for the affected ReduceSerializer paths and thus fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mag 2026

Pagina 1506 di 2983

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.