Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36187 risultati

VulnerabilitàAlta
CVE-2026-28732 - Slash command trigger-word update allowed command hijacking

CVE ID :CVE-2026-28732 Published : May 18, 2026, 9:16 a.m. | 4 hours, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-3117 - Instance and webhook GitLab plugin commands were able to be run by non-admin users

CVE ID :CVE-2026-3117 Published : May 18, 2026, 9:16 a.m. | 4 hours, 55 minutes ago Description :Mattermost Plugins versions Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-3471 - Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App

CVE ID :CVE-2026-3471 Published : May 18, 2026, 9:16 a.m. | 4 hours, 55 minutes ago Description :Mattermost Desktop App versions Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
News
Kritiek beveiligingslek in NGINX-servers actief misbruikt bij aanvallen

Kritiek beveiligingslek in NGINX-servers actief misbruikt bij aanvallen Een kritiek beveiligingslek in NGINX wordt actief misbruikt bij aanvallen. Beheerders worden opgeroepen om de beschikbaar gestelde update voor CVE-2026-42945 te installeren. NGINX is een webserver, re ... Read more Published Date: May 18, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42945

CVEfeed Newsroom18 mag 2026
News
CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks

CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks CISA has issued a fresh warning about a newly disclosed Microsoft Exchange Server vulnerability that is already being exploited in real-world attacks, raising concerns for organizations relying on on- ... Read more Published Date: May 18, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897

CVEfeed Newsroom18 mag 2026
News
1 Million WordPress Sites Affected by Avada Builder File Read and SQL Injection Flaws

1 Million WordPress Sites Affected by Avada Builder File Read and SQL Injection Flaws A widely used WordPress plugin powering over one million websites has been hit by two serious vulnerabilities that could allow attackers to steal sensitive data and access server files. Security resea ... Read more Published Date: May 18, 2026 (2 days, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4798 CVE-2026-4782

CVEfeed Newsroom18 mag 2026
VulnerabilitàAlta
CVE-2026-6379 - WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter

CVE ID :CVE-2026-6379 Published : May 18, 2026, 7:16 a.m. | 55 minutes ago Description :The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-6381 - WP Maps < 4.9.3 - Subscriber+ Local File Inclusion

CVE ID :CVE-2026-6381 Published : May 18, 2026, 7:16 a.m. | 55 minutes ago Description :The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-1631 - Feeds for YouTube < 2.6.4 - Subscriber+ License Data Deletion

CVE ID :CVE-2026-1631 Published : May 18, 2026, 7:16 a.m. | 55 minutes ago Description :The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This makes it possible for subscribers and above delete the license key. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-3220 - Multiple Plugins - Unauthenticated Stored XSS via Minify Library

CVE ID :CVE-2026-3220 Published : May 18, 2026, 7:16 a.m. | 55 minutes ago Description :The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-6495 - Ajax Load More < 7.8.4 - Reflected XSS

CVE ID :CVE-2026-6495 Published : May 18, 2026, 7:16 a.m. | 2 hours, 55 minutes ago Description :The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-6340 - Memory Exhaustion via Malicious 7zip File Upload

CVE ID :CVE-2026-6340 Published : May 18, 2026, 8:16 a.m. | 1 hour, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026

Pagina 1591 di 3016

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.