Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36213 risultati

News
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw ... Read more Published Date: May 18, 2026 (2 days, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897 CVE-2026-41940 CVE-2025-62221 CVE-2020-17103

CVEfeed Newsroom18 mag 2026
VulnerabilitàAlta
CVE-2026-8785 (CVSS 7.3)

A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Parameter Handler. Executing a manipulation of the argument appointment_no can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)18 mag 2026
VulnerabilitàAlta
CVE-2026-8785 - projectworlds hospital-management-system-in-php GET Parameter update_info.php getAllPatientDetail sql injection

CVE ID :CVE-2026-8785 Published : May 18, 2026, 4:16 a.m. | 3 hours, 55 minutes ago Description :A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Parameter Handler. Executing a manipulation of the argument appointment_no can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
News
Critical WordPress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks

Critical WordPress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks A critical vulnerability in a widely used WordPress plugin has exposed over 200,000 websites to full account takeover, raising urgent concerns across the security community. Discovered on May 8, 2026, ... Read more Published Date: May 18, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-8181

CVEfeed Newsroom18 mag 2026
VulnerabilitàAlta
CVE-2026-8786 - Tencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseForInitialization authorization

CVE ID :CVE-2026-8786 Published : May 18, 2026, 4:16 a.m. | 3 hours, 55 minutes ago Description :A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component Config API Endpoint. The manipulation of the argument kbId leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-8784 - npitre cramfs-tools cramfsck.c change_file_status symlink

CVE ID :CVE-2026-8784 Published : May 18, 2026, 4:16 a.m. | 3 hours, 55 minutes ago Description :A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink following. The attack requires a local approach. The exploit is now public and may be used. The patch is named b4a3a695c9873f824907bd15659f2a6ac7667b4f. It is recommended to apply a patch to fix this issue. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-8782 - omec-project amf NGAP Message handler.go null pointer dereference

CVE ID :CVE-2026-8782 Published : May 18, 2026, 2:16 a.m. | 5 hours, 55 minutes ago Description :A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function of the file ngap/handler.go of the component NGAP Message Handler. This manipulation causes null pointer dereference. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.2.0 mitigates this issue. It is recommended to upgrade the affected component. The same pull request fixes multiple security issues. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-8780 - omec-project amf NGAP Message dispatcher.go memory corruption

CVE ID :CVE-2026-8780 Published : May 18, 2026, 2:16 a.m. | 5 hours, 55 minutes ago Description :A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unknown function of the file ngap/dispatcher.go of the component NGAP Message Handler. The manipulation leads to memory corruption. The attack may be initiated remotely. The exploit is publicly available and might be used. Upgrading to version 2.2.0 is sufficient to fix this issue. It is suggested to upgrade the affected component. The same pull request fixes multiple security issues. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-8781 - omec-project amf handler.go RANConfiguration null pointer dereference

CVE ID :CVE-2026-8781 Published : May 18, 2026, 2:16 a.m. | 5 hours, 55 minutes ago Description :A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the function RANConfiguration of the file ngap/handler.go. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.2.0 is sufficient to resolve this issue. Upgrading the affected component is recommended. The same pull request fixes multiple security issues. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026
VulnerabilitàAlta
CVE-2026-8776 (CVSS 8.8)

A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulation of the argument pptpUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)18 mag 2026
VulnerabilitàAlta
CVE-2026-8775 (CVSS 8.8)

A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. This manipulation of the argument L2TPUserName causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)18 mag 2026
VulnerabilitàAlta
CVE-2026-8776 - Edimax BR-6428NS POST Request formPPTPSetup buffer overflow

CVE ID :CVE-2026-8776 Published : May 18, 2026, 2:16 a.m. | 5 hours, 55 minutes ago Description :A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulation of the argument pptpUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE18 mag 2026

Pagina 1595 di 3018

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.