Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36255 risultati

VulnerabilitàAlta
CVE-2026-41967 - "Adobe Manufacturability Design Module Permissions Vulnerability"

CVE ID :CVE-2026-41967 Published : May 15, 2026, 10:16 a.m. | 3 hours, 50 minutes ago Description :Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-41966 - "Microsoft Smart Sensing Service Authorization Bypass"

CVE ID :CVE-2026-41966 Published : May 15, 2026, 10:16 a.m. | 3 hours, 50 minutes ago Description :Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Severity: 5.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-41962 - Apache App Misconfigured Permission Control Vulnerability

CVE ID :CVE-2026-41962 Published : May 15, 2026, 10:16 a.m. | 3 hours, 50 minutes ago Description :Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Severity: 3.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-41961 - Google Contacts Permission Control Vulnerability

CVE ID :CVE-2026-41961 Published : May 15, 2026, 10:16 a.m. | 3 hours, 50 minutes ago Description :Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-41960 - Apache Kafka Kerberos Authentication Bypass

CVE ID :CVE-2026-41960 Published : May 15, 2026, 10:16 a.m. | 3 hours, 50 minutes ago Description :Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-41971 - "Apache Security Control Module Permission Bypass"

CVE ID :CVE-2026-41971 Published : May 15, 2026, 10:16 a.m. | 5 hours, 51 minutes ago Description :Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-7563 - Classified Listing <= 5.3.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via add_order_note and send_email_to_user_by_moderator AJAX Actions

CVE ID :CVE-2026-7563 Published : May 15, 2026, 9:16 a.m. | 4 hours, 50 minutes ago Description :The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to add arbitrary notes to any order and trigger unsolicited notification and moderation emails to listing owners without administrative authorization. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-7046 - NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter

CVE ID :CVE-2026-7046 Published : May 15, 2026, 9:16 a.m. | 4 hours, 50 minutes ago Description :The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-8425 - Notify Odoo <= 1.0.1 - Cross-Site Request Forgery to Settings Update

CVE ID :CVE-2026-8425 Published : May 15, 2026, 9:16 a.m. | 4 hours, 50 minutes ago Description :The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the _updateSettings function. This makes it possible for unauthenticated attackers to change the Notify Odoo URL to an attacker-controlled URL and modify notification, tracking image, and allowed IP address settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-6415 - Advanced Custom Fields: Font Awesome Field <= 5.0.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via JSON Field

CVE ID :CVE-2026-6415 Published : May 15, 2026, 9:16 a.m. | 4 hours, 50 minutes ago Description :The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-8398 - AVB Disc Soft DAEMON Tools Lite Supply Chain Trojanization

CVE ID :CVE-2026-8398 Published : May 15, 2026, 9:16 a.m. | 4 hours, 50 minutes ago Description :A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE15 mag 2026
VulnerabilitàAlta
CVE-2026-6403 (CVSS 7.5)

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path without sanitizing directory traversal sequences. This makes it possible for unauthenticated attackers to trigger the creation of a ZIP archive containing arbitrary files from the server's filesystem — including wp-config.

NVD (NIST)15 mag 2026

Pagina 1624 di 3022

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.