News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
45088 risultati
Check Point meldt actief misbruik van kritieke vpn-kwetsbaarheid Cybersecuritybedrijf Check Point waarschuwt voor actief misbruik van een kritieke kwetsbaarheid in de vpn-producten die het biedt. Via het beveiligingslek (CVE-2026-85102) kan een ongeauthenticeerde a ... Read more Published Date: Sep 24, 2026 (4 days, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-93616 CVE-2026-85102
A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.
CVE ID :CVE-2026-78312 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78313 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-85682 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97185 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78311 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78308 Published : Sept. 24, 2026, 9:17 a.m. | 1 hour, 30 minutes ago Description :Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78309 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78310 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Pagina 162 di 3758