News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36187 risultati
CVE ID :CVE-2026-46723 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-45187 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-46721 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-46586 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-45434 Published : May 19, 2026, 10:16 a.m. | 1 hour, 57 minutes ago Description :Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities in Sparx Systems products Vulnerabilities in Sparx Systems products CVE ID CVE-2026-42096 Publication date 19 May 2026 Vendor Sparx Systems Product Pro Cloud Server Vulnerable versions All through 6.1 Vulnerability type (CWE) ... Read more Published Date: May 19, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article.
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enabl ... Read more Published Date: May 19, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897 CVE-2026-7864 CVE-2026-44129 CVE-2026-44128 CVE-2026-44127 CVE-2026-44126 CVE-2026-44125 CVE-2026-41940 CVE-2026-2743 CVE-2026-27441
CVE ID :CVE-2026-44408 Published : May 19, 2026, 9:16 a.m. | 57 minutes ago Description :There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form.
CVE ID :CVE-2026-4885 Published : May 19, 2026, 8:16 a.m. | 1 hour, 57 minutes ago Description :The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical NGINX Vulnerability CVE-2026-42945 Now Under Active Attack Cybersecurity researchers are warning that attackers have already started exploiting a newly disclosed NGINX vulnerability, tracked as CVE-2026-42945, just days after technical details and proof-of-co ... Read more Published Date: May 19, 2026 (2 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-42945 CVE-2026-31431
CVE ID :CVE-2026-8830 Published : May 19, 2026, 7:16 a.m. | 2 hours, 57 minutes ago Description :A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential's parameters, such as public key algorithms, match the realm's configured WebAuthn policies. This could lead to the creation of credentials that do not adhere to administrative security requirements, potentially weakening the overall security posture of the system by allowing non-compliant authentication methods. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1580 di 3016