Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35841 risultati

VulnerabilitàAlta
CVE-2026-29518 - Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write

CVE ID :CVE-2026-29518 Published : May 20, 2026, 1:16 p.m. | 59 minutes ago Description :Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-27424 - WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Broken Access Control vulnerability

CVE ID :CVE-2026-27424 Published : May 20, 2026, 1:16 p.m. | 59 minutes ago Description :Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-27405 - WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability

CVE ID :CVE-2026-27405 Published : May 20, 2026, 1:16 p.m. | 59 minutes ago Description :Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-24573 - WordPress Visualizer plugin < 4.0.0 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-24573 Published : May 20, 2026, 1:16 p.m. | 59 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2025-11954 (CVSS 8)

Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)20 mag 2026
VulnerabilitàAlta
CVE-2025-11954 - CSRF in Sitemio's WISECP

CVE ID :CVE-2025-11954 Published : May 20, 2026, 1:16 p.m. | 59 minutes ago Description :Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2025-31985 - HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header

CVE ID :CVE-2025-31985 Published : May 20, 2026, 12:16 p.m. | 1 hour, 58 minutes ago Description :HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2025-31973 - HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'

CVE ID :CVE-2025-31973 Published : May 20, 2026, 11:25 a.m. | 49 minutes ago Description :HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-22315 - Mesalvo Meona Client Launcher/Mesalvo Meona Server Privilege Escalation and Data Exfiltration Vulnerability

CVE ID :CVE-2026-22315 Published : May 20, 2026, 11:16 a.m. | 58 minutes ago Description :Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export of user data, including cleartext passwords, via the SQL editor. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-25602 - Mesalvo Meona Email Spoofing Vulnerability

CVE ID :CVE-2026-25602 Published : May 20, 2026, 11:16 a.m. | 58 minutes ago Description :Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email address. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-22314 - Mesalvo Meona Client Launcher Component and Mesalvo Meona Server Component Code Injection Vulnerability

CVE ID :CVE-2026-22314 Published : May 20, 2026, 11:16 a.m. | 58 minutes ago Description :Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. Severity: 9.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-0856 - Mesalvo Meona Client/Server Unauthenticated Admin Panel Access

CVE ID :CVE-2026-0856 Published : May 20, 2026, 11:16 a.m. | 58 minutes ago Description :Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026

Pagina 1531 di 2987

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.