Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36162 risultati

News
PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability

PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2005, a critical remote code execution (RCE) vulnerability affecting PostgreSQL’s pgcrypto extension. The flaw, rooted in legac ... Read more Published Date: May 20, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-2005

CVEfeed Newsroom20 mag 2026
VulnerabilitàAlta
CVE-2026-9010 (CVSS 7.5)

The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)20 mag 2026
VulnerabilitàAlta
CVE-2026-9003 (CVSS 7.5)

E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

NVD (NIST)20 mag 2026
VulnerabilitàAlta
CVE-2026-9010 - Boost <= 2.0.3 - Unauthenticated Blind SQL Injection via Multiple Parameters

CVE ID :CVE-2026-9010 Published : May 20, 2026, 4:16 a.m. | 3 hours, 58 minutes ago Description :The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-9003 - TONNET|E-LAN Hybrid Recording System - SQL Injection

CVE ID :CVE-2026-9003 Published : May 20, 2026, 4:16 a.m. | 3 hours, 58 minutes ago Description :E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàCritica
CVE-2026-7637 (CVSS 9.8)

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

NVD (NIST)20 mag 2026
VulnerabilitàAlta
CVE-2026-7637 - Boost <= 2.0.3 - Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_LOCATION Cookie

CVE ID :CVE-2026-7637 Published : May 20, 2026, 4:16 a.m. | 3 hours, 58 minutes ago Description :The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-24163 - NVIDIA TRT-LLM RPC Deserialization Vulnerability

CVE ID :CVE-2026-24163 Published : May 20, 2026, 4:16 a.m. | 1 hour, 58 minutes ago Description :NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-24160 - NVIDIA TRT-LLM Null Pointer Dereference Denial of Service

CVE ID :CVE-2026-24160 Published : May 20, 2026, 4:16 a.m. | 1 hour, 58 minutes ago Description :NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-24142 - NVIDIA TRT-LLM Deserialization RCE and Tampering Vulnerability

CVE ID :CVE-2026-24142 Published : May 20, 2026, 4:16 a.m. | 1 hour, 58 minutes ago Description :NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2025-33255 - NVIDIA TRT-LLM MPI Server Deserialization Vulnerability

CVE ID :CVE-2025-33255 Published : May 20, 2026, 4:16 a.m. | 1 hour, 58 minutes ago Description :NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026
VulnerabilitàAlta
CVE-2026-24215 - NVIDIA Triton Inference Server Resource Consumption Denial of Service

CVE ID :CVE-2026-24215 Published : May 20, 2026, 4:16 a.m. | 3 hours, 58 minutes ago Description :NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 mag 2026

Pagina 1562 di 3014

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.