Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33708 risultati

VulnerabilitàAlta
CVE-2026-16574 - Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint

CVE ID :CVE-2026-16574 Published : Aug. 8, 2026, 7:17 a.m. | 7 hours, 8 minutes ago Description :The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-16578 - Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route

CVE ID :CVE-2026-16578 Published : Aug. 8, 2026, 7:17 a.m. | 9 hours, 8 minutes ago Description :The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles, and two-factor authentication enrollment status. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-16589 - WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter

CVE ID :CVE-2026-16589 Published : Aug. 8, 2026, 7:17 a.m. | 9 hours, 8 minutes ago Description :The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-16590 - WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure

CVE ID :CVE-2026-16590 Published : Aug. 8, 2026, 7:17 a.m. | 9 hours, 8 minutes ago Description :The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-16594 - WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure

CVE ID :CVE-2026-16594 Published : Aug. 8, 2026, 7:17 a.m. | 9 hours, 8 minutes ago Description :The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-16282 - Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter

CVE ID :CVE-2026-16282 Published : Aug. 8, 2026, 7:17 a.m. | 5 hours, 8 minutes ago Description :The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-16267 - Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field

CVE ID :CVE-2026-16267 Published : Aug. 8, 2026, 7:17 a.m. | 3 hours, 8 minutes ago Description :The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-16269 - Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling

CVE ID :CVE-2026-16269 Published : Aug. 8, 2026, 7:17 a.m. | 5 hours, 8 minutes ago Description :The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàCritica
CVE-2026-14526 (CVSS 9.8)

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-level user account and achieve full site takeover by saving and executing a malicious workflow containing a wp_create_user action node specifying role=administrator. This vulnerability is exploitable by unauthenticated attackers on any site where the [aiwu-form] shortcode or public chatbot is rendered on a frontend page, as the waic-nonce value is emitted into publicly accessible JavaScript (WAIC_DATA.waicNonce) on those pages, rendering the nonce check a non-functional authorization barrier.

NVD (NIST)08 ago 2026
VulnerabilitàAlta
CVE-2026-14526 - AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route

CVE ID :CVE-2026-14526 Published : Aug. 8, 2026, 7:17 a.m. | 3 hours, 8 minutes ago Description :The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-level user account and achieve full site takeover by saving and executing a malicious workflow containing a wp_create_user action node specifying role=administrator. This vulnerability is exploitable by unauthenticated attackers on any site where the [aiwu-form] shortcode or public chatbot is rendered on a frontend page, as the waic-nonce value is emitted into publicly accessible JavaScript (WAIC_DATA.waicNonce) on those pages, rendering the nonce check a non-functional authorization barrier. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-19266 - Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection

CVE ID :CVE-2026-19266 Published : Aug. 8, 2026, 8:16 a.m. | 8 hours, 8 minutes ago Description :A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue. This patch is called e0729dcfd3a2b1682a7bff86e7174852c03419ba. It is advisable to upgrade the affected component. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
News
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (C ... Read more Published Date: Aug 08, 2026 (3 days, 14 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-50522 CVE-2023-38646

CVEfeed Newsroom08 ago 2026

Pagina 156 di 2809

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.