Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36213 risultati

VulnerabilitàAlta
CVE-2018-25327 - Joomla! Component Js Jobs 1.2.0 Cross-Site Request Forgery

CVE ID :CVE-2018-25327 Published : May 17, 2026, 1:16 p.m. | 8 hours, 54 minutes ago Description :Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify component settings when administrators visit attacker-controlled pages. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2018-25332 - GitBucket 4.23.1 Unauthenticated Remote Code Execution

CVE ID :CVE-2018-25332 Published : May 17, 2026, 1:16 p.m. | 8 hours, 54 minutes ago Description :GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. Attackers can brute-force the Blowfish encryption key, upload a malicious JAR plugin via the git-lfs endpoint, and execute system commands through an exposed exploit endpoint. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2018-25330 - Joomla! EkRishta 2.10 Persistent XSS and SQL Injection

CVE ID :CVE-2018-25330 Published : May 17, 2026, 1:16 p.m. | 8 hours, 54 minutes ago Description :Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile, or submit SQL injection payloads via the phone_no parameter to the user_setting endpoint to manipulate database queries. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2018-25333 - Nordex N149/4.0-4.5 Wind Turbine Web Server SQL Injection

CVE ID :CVE-2018-25333 Published : May 17, 2026, 1:16 p.m. | 8 hours, 54 minutes ago Description :Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the login parameter in login.php. Attackers can submit crafted POST requests with SQL injection payloads in the login field to extract sensitive database information and bypass authentication mechanisms. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2018-25331 - Zenar Content Management System Cross-Site Scripting via ajax.php

CVE ID :CVE-2018-25331 Published : May 17, 2026, 1:16 p.m. | 8 hours, 54 minutes ago Description :Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.php endpoint, which reflects unsanitized user input in the response HTML to execute arbitrary JavaScript in victim browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2018-25329 - WordPress Plugin WP with Spritz 1.0 Remote File Inclusion

CVE ID :CVE-2018-25329 Published : May 17, 2026, 1:16 p.m. | 8 hours, 54 minutes ago Description :WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attackers can send GET requests to wp.spritz.content.filter.php with malicious url values to access sensitive files like system configuration and credentials. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2018-25328 - VX Search 10.6.18 Local Buffer Overflow via Directory Field

CVE ID :CVE-2018-25328 Published : May 17, 2026, 1:16 p.m. | 8 hours, 54 minutes ago Description :VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craft a malicious input file containing 271 bytes of junk data followed by a return address to execute arbitrary code with application privileges. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2018-25326 - Google Drive for WordPress 2.2 Path Traversal RCE via gdrive-ajaxs.php

CVE ID :CVE-2018-25326 Published : May 17, 2026, 1:16 p.m. | 8 hours, 54 minutes ago Description :Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_bkp and file_name containing traversal sequences ../../wp-config.php to access sensitive configuration files. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE17 mag 2026
VulnerabilitàAlta
CVE-2018-25325 (CVSS 7.5)

Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename parameter to delete sensitive files like wp-config.php outside the intended export directory.

NVD (NIST)17 mag 2026
VulnerabilitàAlta
CVE-2018-25323 (CVSS 8.4)

Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a text file with a specially crafted buffer containing shellcode and SEH chain overwrite values, then paste the contents into the License Name field to trigger code execution.

NVD (NIST)17 mag 2026
VulnerabilitàAlta
CVE-2018-25322 (CVSS 8.4)

Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can craft a payload with 780 bytes of junk data followed by structured shellcode and place it in the License Name field to trigger the overflow and execute code with application privileges.

NVD (NIST)17 mag 2026
VulnerabilitàCritica
CVE-2018-25320 (CVSS 9.8)

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control.

NVD (NIST)17 mag 2026

Pagina 1600 di 3018

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.