Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36162 risultati

VulnerabilitàAlta
CVE-2026-31072 - Apache APScheduler Python RCE via Insecure Deserialization

CVE ID :CVE-2026-31072 Published : May 19, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantiation and state injection by dynamically importing modules and calling __setstate__ on any class available in the Python environment. An attacker can exploit this by submitting a specially crafted JSON or CBOR payload to an application using these serializers Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-31071 - LalanaChami Pharmacy Management System Unauthenticated API Endpoint Vulnerability

CVE ID :CVE-2026-31071 Published : May 19, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserData, modify drug inventory, and access private medical prescription data via /api/doctorOder. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-30118 - Scalar Astro SSRF

CVE ID :CVE-2026-30118 Published : May 19, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers to force the backend server to send HTTP requests to attacker-controlled URLs, leading to authentication cookies and headers exposure and possible privilege escalation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-31070 - LalanaChami Pharmacy Management System Privilege Escalation Vulnerability

CVE ID :CVE-2026-31070 Published : May 19, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-31069 - BillaBear SQL Injection Vulnerability

CVE ID :CVE-2026-31069 Published : May 19, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although filter values are parameterized, the filter identifiers (keys) are not. An authenticated attacker with ROLE_ACCOUNT_MANAGER permissions can exploit this to execute arbitrary SQL commands. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-30117 - Scalar Astro Arbitrary File Upload Vulnerability

CVE ID :CVE-2026-30117 Published : May 19, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execute arbitrary code via uploading a crafted SVG file. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
News
Critical PostgreSQL Vulnerabilities Enables Code Execution and SQL Injections

Critical PostgreSQL Vulnerabilities Enables Code Execution and SQL Injections The PostgreSQL Global Development Group has released critical security updates for all supported branches, fixing 11 vulnerabilities, including arbitrary code execution and several SQL injection flaws ... Read more Published Date: May 19, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-6638 CVE-2026-6637 CVE-2026-6575 CVE-2026-6479 CVE-2026-6478 CVE-2026-6477 CVE-2026-6476 CVE-2026-6475 CVE-2026-6474 CVE-2026-6473 CVE-2026-6472

CVEfeed Newsroom19 mag 2026
VulnerabilitàAlta
CVE-2026-8711 (CVSS 8.1)

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

NVD (NIST)19 mag 2026
VulnerabilitàAlta
CVE-2026-8711 - NGINX JavaScript vulnerability

CVE ID :CVE-2026-8711 Published : May 19, 2026, 3:16 p.m. | 2 hours, 58 minutes ago Description :NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-47100 (CVSS 7.5)

Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.

NVD (NIST)19 mag 2026
VulnerabilitàAlta
CVE-2026-47100 - Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX

CVE ID :CVE-2026-47100 Published : May 19, 2026, 3:16 p.m. | 57 minutes ago Description :Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-43634 (CVSS 7.5)

HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's network. Attackers can exploit this to circumvent fail2ban brute-force protection, bypass per-user IP allowlists, and poison authentication audit logs by spoofing trusted IP addresses on each request.

NVD (NIST)19 mag 2026

Pagina 1571 di 3014

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.