Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36213 risultati

VulnerabilitàAlta
CVE-2021-47975 - WordPress Plugin WP Learn Manager 1.1.2 Stored XSS

CVE ID :CVE-2021-47975 Published : May 16, 2026, 4:16 p.m. | 15 hours, 54 minutes ago Description :WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter. Attackers can submit POST requests to the jslm_fieldordering page with XSS payloads in the fieldtitle field to execute arbitrary JavaScript when administrators view the field ordering interface. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2021-47956 (CVSS 8.2)

EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the firstname parameter. Attackers can send POST requests to insert.php with malicious firstname values to extract sensitive database information.

NVD (NIST)16 mag 2026
VulnerabilitàAlta
CVE-2021-47954 (CVSS 8.2)

LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the search_query parameter. Attackers can send POST requests to /search.php with malicious search_query values using CASE WHEN statements to extract sensitive database information.

NVD (NIST)16 mag 2026
VulnerabilitàCritica
CVE-2021-47952 (CVSS 9.8)

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute system commands and arbitrary code.

NVD (NIST)16 mag 2026
VulnerabilitàAlta
CVE-2021-47942 (CVSS 7.5)

Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances.

NVD (NIST)16 mag 2026
VulnerabilitàAlta
CVE-2020-37247 (CVSS 7.8)

Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.

NVD (NIST)16 mag 2026
VulnerabilitàAlta
CVE-2021-47954 - LayerBB 1.1.4 SQL Injection via search_query Parameter

CVE ID :CVE-2021-47954 Published : May 16, 2026, 4:16 p.m. | 11 hours, 54 minutes ago Description :LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the search_query parameter. Attackers can send POST requests to /search.php with malicious search_query values using CASE WHEN statements to extract sensitive database information. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2021-47956 - EgavilanMedia PHPCRUD 1.0 SQL Injection via firstname

CVE ID :CVE-2021-47956 Published : May 16, 2026, 4:16 p.m. | 11 hours, 54 minutes ago Description :EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the firstname parameter. Attackers can send POST requests to insert.php with malicious firstname values to extract sensitive database information. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2020-37247 - Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation

CVE ID :CVE-2020-37247 Published : May 16, 2026, 4:16 p.m. | 7 hours, 54 minutes ago Description :Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2021-47942 - Home Assistant Community Store 1.10.0 Path Traversal Account Takeover

CVE ID :CVE-2021-47942 Published : May 16, 2026, 4:16 p.m. | 9 hours, 54 minutes ago Description :Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2021-47952 - python jsonpickle 2.0.0 Remote Code Execution via py/repr

CVE ID :CVE-2021-47952 Published : May 16, 2026, 4:16 p.m. | 11 hours, 54 minutes ago Description :python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute system commands and arbitrary code. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2020-37245 (CVSS 7.5)

Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stored cross-site scripting attacks through script injection in parameters like Area Width and Publication Width that execute when publications are viewed or edited.

NVD (NIST)16 mag 2026

Pagina 1606 di 3018

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.