Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36235 risultati

VulnerabilitàAlta
CVE-2020-37241 - bloofoxCMS 0.5.2.1 Cross-Site Request Forgery via user add

CVE ID :CVE-2020-37241 Published : May 16, 2026, 3:28 p.m. | 42 minutes ago Description :bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can craft hidden forms targeting the admin user creation endpoint to add new administrative accounts with arbitrary credentials without requiring explicit user consent. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2021-47981 - Quick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form

CVE ID :CVE-2021-47981 Published : May 16, 2026, 4:16 p.m. | 17 hours, 54 minutes ago Description :Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript in victim browsers when the form is submitted. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2021-47957 - WordPress Plugin Cookie Law Bar 1.2.1 Stored XSS via clb_bar_msg

CVE ID :CVE-2021-47957 Published : May 16, 2026, 4:16 p.m. | 13 hours, 54 minutes ago Description :Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Attackers can inject script payloads through the plugin settings page that execute in the browsers of all WordPress users viewing the site, enabling cookie theft and sensitive data exfiltration. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2021-47955 - CouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload

CVE ID :CVE-2021-47955 Published : May 16, 2026, 4:16 p.m. | 11 hours, 54 minutes ago Description :CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality. Attackers can upload SVG files containing embedded script tags to the browse.php endpoint, which are then executed in users' browsers when the files are accessed or previewed. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2021-47934 - MyBB Timeline Plugin 1.0 Cross-Site Scripting and CSRF

CVE ID :CVE-2021-47934 Published : May 16, 2026, 4:16 p.m. | 9 hours, 54 minutes ago Description :MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profile action to change a user's cover picture by crafting malicious forms that execute when victims visit affected profiles. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2020-37246 - WordPress Plugin Supsystic Backup 2.3.9 Local File Inclusion

CVE ID :CVE-2020-37246 Published : May 16, 2026, 4:16 p.m. | 7 hours, 54 minutes ago Description :Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like /etc/passwd or delete files via the removeAction parameter. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2026-46719 - Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections

CVE ID :CVE-2026-46719 Published : May 16, 2026, 1:37 p.m. | 32 minutes ago Description :Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2025-4202 - Multicollab: Content Team Collaboration and Editorial Workflow <= 5.2 - Missing Authorization to Authenticated (Subscriber+) Collaboration Comment

CVE ID :CVE-2025-4202 Published : May 16, 2026, 1:16 p.m. | 53 minutes ago Description :The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf_add_comment' function in all versions up to, and including, 5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add comments to arbitrary collaborations. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
News
Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities

Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities Two critical memory-safety vulnerabilities in PHP’s image-processing functions could allow attackers to leak sensitive heap memory or to execute denial-of-service attacks via specially crafted JPEG fi ... Read more Published Date: May 16, 2026 (3 days, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-14177

CVEfeed Newsroom16 mag 2026
News
Linux Kernel Vulnerability “ssh-keysign-pwn” Lets Attackers Read SSH Keys and Shadow Passwords

Linux Kernel Vulnerability “ssh-keysign-pwn” Lets Attackers Read SSH Keys and Shadow Passwords A newly disclosed Linux kernel vulnerability is raising serious concerns across the security community, as it allows attackers to access highly sensitive data, including SSH private keys and password ... Read more Published Date: May 16, 2026 (3 days, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-46333

CVEfeed Newsroom16 mag 2026
VulnerabilitàAlta
CVE-2026-8657 - Apache jsondiffpatch Prototype Pollution Vulnerability

CVE ID :CVE-2026-8657 Published : May 16, 2026, 6:16 a.m. | 7 hours, 53 minutes ago Description :Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property names and path segments are used to traverse and modify objects without restricting access to special properties like __proto__ or constructor.prototype, allowing modification of Object.prototype. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026
VulnerabilitàAlta
CVE-2026-8656 - Jsondiffpatch Cross-Site Scripting (XSS)

CVE ID :CVE-2026-8656 Published : May 16, 2026, 6:16 a.m. | 7 hours, 53 minutes ago Description :Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an application compares untrusted JSON/object data and renders annotated formatter output in the DOM, attacker-controlled HTML can be interpreted by the browser, resulting in XSS. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 mag 2026

Pagina 1610 di 3020

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.