Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36187 risultati

VulnerabilitàAlta
CVE-2026-46723 - Information Disclosure in extension "Faceted Search" (ke_search)

CVE ID :CVE-2026-46723 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-45187 - Apache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System Jobs

CVE ID :CVE-2026-45187 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-46721 - Broken Access Control in extension "Frontend User Registration" (sf_register)

CVE ID :CVE-2026-46721 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-46586 - Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution

CVE ID :CVE-2026-46586 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàAlta
CVE-2026-45434 - Apache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCE

CVE ID :CVE-2026-45434 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
News
Vulnerabilities in Sparx Systems products

Vulnerabilities in Sparx Systems products Vulnerabilities in Sparx Systems products CVE ID CVE-2026-42096 Publication date 19 May 2026 Vendor Sparx Systems Product Pro Cloud Server Vulnerable versions All through 6.1 Vulnerability type (CWE) ... Read more Published Date: May 19, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom19 mag 2026
News
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enabl ... Read more Published Date: May 19, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897 CVE-2026-7864 CVE-2026-44129 CVE-2026-44128 CVE-2026-44127 CVE-2026-44126 CVE-2026-44125 CVE-2026-41940 CVE-2026-2743 CVE-2026-27441

CVEfeed Newsroom19 mag 2026
VulnerabilitàAlta
CVE-2026-44408 - Unauthorized access vulnerability in ZTE MU5250

CVE ID :CVE-2026-44408 Published : May 19, 2026, 9:16 a.m. | 57 minutes ago Description :There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
VulnerabilitàCritica
CVE-2026-4885 (CVSS 9.8)

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form.

NVD (NIST)19 mag 2026
VulnerabilitàAlta
CVE-2026-4885 - Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload

CVE ID :CVE-2026-4885 Published : May 19, 2026, 8:16 a.m. | 1 hour, 57 minutes ago Description :The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026
News
Critical NGINX Vulnerability CVE-2026-42945 Now Under Active Attack

Critical NGINX Vulnerability CVE-2026-42945 Now Under Active Attack Cybersecurity researchers are warning that attackers have already started exploiting a newly disclosed NGINX vulnerability, tracked as CVE-2026-42945, just days after technical details and proof-of-co ... Read more Published Date: May 19, 2026 (2 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-42945 CVE-2026-31431

CVEfeed Newsroom19 mag 2026
VulnerabilitàAlta
CVE-2026-8830 - Keycloak: org.keycloak/keycloak-services: keycloak: policy bypass during webauthn credential registration via client-side javascript manipulation

CVE ID :CVE-2026-8830 Published : May 19, 2026, 7:16 a.m. | 2 hours, 57 minutes ago Description :A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential's parameters, such as public key algorithms, match the realm's configured WebAuthn policies. This could lead to the creation of credentials that do not adhere to administrative security requirements, potentially weakening the overall security posture of the system by allowing non-compliant authentication methods. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 mag 2026

Pagina 1580 di 3016

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.