News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36255 risultati
Cisco waarschuwt voor actief misbruikt lek in Catalyst SD-WAN Controller Cisco waarschuwt voor een actief misbruikte kwetsbaarheid in de Catalyst SD-WAN Controller waardoor een ongeauthenticeerde aanvaller admin-toegang tot het systeem kan krijgen. Er zijn beveiligingsupda ... Read more Published Date: May 15, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20182
79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now! Google has rolled out a massive security update for its Chrome browser, sealing a staggering 79 vulnerabilities before threat actors can exploit them. With 14 of these flaws rated as critical, browsin ... Read more Published Date: May 15, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-8522 CVE-2026-8521 CVE-2026-8520 CVE-2026-8519 CVE-2026-8518 CVE-2026-8517 CVE-2026-8516 CVE-2026-8515 CVE-2026-8514 CVE-2026-8513 CVE-2026-8512 CVE-2026-8511 CVE-2026-8510 CVE-2026-8509 CVE-2026-41940
Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks Microsoft issued an urgent security alert regarding a newly discovered vulnerability in Exchange Server that is currently being exploited in the wild. Tracked as CVE-2026-42897, this critical spoofing ... Read more Published Date: May 15, 2026 (2 days, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897
Critical Next.js Vulnerability Exposes Cloud Credentials, API keys, and Admin Panels A high-severity vulnerability in Next.js threatens self-hosted web applications with severe data breaches. Threat actors can now exploit a Server-Side Request Forgery (SSRF) flaw to silently steal clo ... Read more Published Date: May 15, 2026 (2 days, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-44578
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page with the `woocs_reset` parameter appended. Additionally, because no nonce is verified, this is also exploitable via Cross-Site Request Forgery against any administrator. The vulnerability may also be exploited by Subscriber-level users if the site is configured to allow Subscriber access to 'wp-admin' pages.
CVE ID :CVE-2026-6646 Published : May 15, 2026, 7:16 a.m. | 2 hours, 50 minutes ago Description :The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitization and output escaping on the 'title' component of the 'link' shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-8654 Published : May 15, 2026, 7:16 a.m. | 4 hours, 50 minutes ago Description :Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4094 Published : May 15, 2026, 7:16 a.m. | 2 hours, 50 minutes ago Description :The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page with the `woocs_reset` parameter appended. Additionally, because no nonce is verified, this is also exploitable via Cross-Site Request Forgery against any administrator. The vulnerability may also be exploited by Subscriber-level users if the site is configured to allow Subscriber access to 'wp-admin' pages. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41702 Published : May 15, 2026, 7:16 a.m. | 50 minutes ago Description :VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Root Access Race: TOCTOU Vulnerability (CVE-2026-41702) Hits VMware Fusion Broadcom has recently issued a critical alert and accompanying patches for VMware Fusion, addressing a local privilege escalation vulnerability that exploits a split-second lapse in the software’s def ... Read more Published Date: May 15, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article.
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-202 ... Read more Published Date: May 15, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897 CVE-2026-23918
CVE ID :CVE-2026-28761 Published : May 15, 2026, 6:16 a.m. | 1 hour, 50 minutes ago Description :Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1626 di 3022