News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36187 risultati
CVE ID :CVE-2026-28732 Published : May 18, 2026, 9:16 a.m. | 4 hours, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-3117 Published : May 18, 2026, 9:16 a.m. | 4 hours, 55 minutes ago Description :Mattermost Plugins versions Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-3471 Published : May 18, 2026, 9:16 a.m. | 4 hours, 55 minutes ago Description :Mattermost Desktop App versions Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Kritiek beveiligingslek in NGINX-servers actief misbruikt bij aanvallen Een kritiek beveiligingslek in NGINX wordt actief misbruikt bij aanvallen. Beheerders worden opgeroepen om de beschikbaar gestelde update voor CVE-2026-42945 te installeren. NGINX is een webserver, re ... Read more Published Date: May 18, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42945
CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks CISA has issued a fresh warning about a newly disclosed Microsoft Exchange Server vulnerability that is already being exploited in real-world attacks, raising concerns for organizations relying on on- ... Read more Published Date: May 18, 2026 (2 days, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897
1 Million WordPress Sites Affected by Avada Builder File Read and SQL Injection Flaws A widely used WordPress plugin powering over one million websites has been hit by two serious vulnerabilities that could allow attackers to steal sensitive data and access server files. Security resea ... Read more Published Date: May 18, 2026 (2 days, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4798 CVE-2026-4782
CVE ID :CVE-2026-6379 Published : May 18, 2026, 7:16 a.m. | 55 minutes ago Description :The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6381 Published : May 18, 2026, 7:16 a.m. | 55 minutes ago Description :The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-1631 Published : May 18, 2026, 7:16 a.m. | 55 minutes ago Description :The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This makes it possible for subscribers and above delete the license key. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-3220 Published : May 18, 2026, 7:16 a.m. | 55 minutes ago Description :The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6495 Published : May 18, 2026, 7:16 a.m. | 2 hours, 55 minutes ago Description :The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6340 Published : May 18, 2026, 8:16 a.m. | 1 hour, 55 minutes ago Description :Mattermost versions 11.5.x Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1591 di 3016