Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35818 risultati

VulnerabilitàAlta
CVE-2026-9116 - Google Chrome ServiceWorker Cross-Origin Data Leaking Vulnerability

CVE ID :CVE-2026-9116 Published : May 20, 2026, 8:16 p.m. | 1 hour, 59 minutes ago Description :Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-39850 - Yii 2: Local file inclusion via view parameter name collision

CVE ID :CVE-2026-39850 Published : May 20, 2026, 7:51 p.m. | 24 minutes ago Description :Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled _file_ key in the $params array overwrites the internal local variable specifying which file to include, potentially enabling RCE if an attacker can write PHP files through a separate primitive, as well as information disclosure. This issue has been fixed in version 2.0.55. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-35016 - Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter

CVE ID :CVE-2026-35016 Published : May 20, 2026, 7:41 p.m. | 34 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_query POST parameter directly into an HTML input field VALUE attribute. Attackers can craft a malicious request containing a JavaScript payload in the frm_query parameter that executes in the victim's browser when submitted. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-35015 - Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Parameter

CVE ID :CVE-2026-35015 Published : May 20, 2026, 7:40 p.m. | 34 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the the_ticket GET parameter directly into a JavaScript variable assignment. Attackers can craft a malicious URL containing a JavaScript payload in the the_ticket parameter that executes in the victim's browser when the URL is visited. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-35014 - Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter

CVE ID :CVE-2026-35014 Published : May 20, 2026, 7:40 p.m. | 35 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers can craft a malicious URL containing a JavaScript payload in the ticket_id parameter that executes in the victim's browser when the URL is visited. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-35013 - Open ISES Tickets < 3.44.2 Reflected XSS via street_view.php thelat and thelng Parameters

CVE ID :CVE-2026-35013 Published : May 20, 2026, 7:39 p.m. | 36 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows authenticated attackers to inject arbitrary JavaScript by passing unsanitized values through the thelat and thelng GET parameters directly into JavaScript variable assignments. Attackers can craft a malicious URL containing a JavaScript payload in either parameter that executes in the victim's browser when the URL is visited. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-35012 - Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter

CVE ID :CVE-2026-35012 Published : May 20, 2026, 7:38 p.m. | 37 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers can craft a malicious URL containing a JavaScript payload in the ticket_id parameter that executes in the victim's browser when the URL is visited. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-9133 - Arbitrary file read in rabbitmq-aws plugin

CVE ID :CVE-2026-9133 Published : May 20, 2026, 8:16 p.m. | 8 hours ago Description :Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aws. If RabbitMQ is configured to use TLS for connections, we also recommend rotating any associated private certificate keys. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-35011 - Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter

CVE ID :CVE-2026-35011 Published : May 20, 2026, 7:37 p.m. | 38 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_call GET parameter directly into page output. Attackers can craft a malicious URL containing a JavaScript payload in the frm_call parameter that executes in the victim's browser when the URL is visited. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-35010 - Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter

CVE ID :CVE-2026-35010 Published : May 20, 2026, 7:36 p.m. | 39 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a JavaScript variable assignment. Attackers can craft a malicious URL containing a JavaScript payload in the ticket_id parameter that executes in the victim's browser when the URL is visited. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-35009 - Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter

CVE ID :CVE-2026-35009 Published : May 20, 2026, 7:36 p.m. | 39 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers can craft a malicious URL containing a JavaScript payload in the ticket_id parameter that executes in the victim's browser when the URL is visited. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-35008 - Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter

CVE ID :CVE-2026-35008 Published : May 20, 2026, 7:34 p.m. | 41 minutes ago Description :Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into an HTML attribute. Attackers can craft a malicious URL containing a JavaScript payload in the id parameter that executes in the victim's browser when the URL is visited. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026

Pagina 1522 di 2985

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.