Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45088 risultati

News
Check Point meldt actief misbruik van kritieke vpn-kwetsbaarheid

Check Point meldt actief misbruik van kritieke vpn-kwetsbaarheid Cybersecuritybedrijf Check Point waarschuwt voor actief misbruik van een kritieke kwetsbaarheid in de vpn-producten die het biedt. Via het beveiligingslek (CVE-2026-85102) kan een ongeauthenticeerde a ... Read more Published Date: Sep 24, 2026 (4 days, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-93616 CVE-2026-85102

CVEfeed Newsroom24 set 2026
VulnerabilitàAlta
CVE-2026-97185 (CVSS 7.8)

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.

NVD (NIST)24 set 2026
VulnerabilitàAlta
CVE-2026-85682 (CVSS 8.8)

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.

NVD (NIST)24 set 2026
VulnerabilitàAlta
CVE-2026-78312 - Path Traversal in DIAEnergie

CVE ID :CVE-2026-78312 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-78313 - Improper Access Control in DIAEnergie

CVE ID :CVE-2026-78313 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-85682 - YOP Poll <= 7.0.10 - Unauthenticated Origin Validation Error to Administrator Account Takeover via '/auth/wp-login-redirect' REST Route

CVE ID :CVE-2026-85682 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-97185 - Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file

CVE ID :CVE-2026-97185 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-78311 - SQL Injection in DIAEnergie

CVE ID :CVE-2026-78311 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-78308 - Authentication Bypass in DIAEnergie

CVE ID :CVE-2026-78308 Published : Sept. 24, 2026, 9:17 a.m. | 1 hour, 30 minutes ago Description :Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-78309 - SQL Injection in DIAEnergie

CVE ID :CVE-2026-78309 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-78310 - Authorization Bypass Through User-Controlled Key in DIAEnergie

CVE ID :CVE-2026-78310 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-77193 (CVSS 7.5)

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

NVD (NIST)24 set 2026

Pagina 162 di 3758

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.