News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
45094 risultati
CVE ID :CVE-2026-85682 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97185 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78311 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78308 Published : Sept. 24, 2026, 9:17 a.m. | 1 hour, 30 minutes ago Description :Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78309 Published : Sept. 24, 2026, 9:17 a.m. | 3 hours, 42 minutes ago Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
CVE ID :CVE-2026-77193 Published : Sept. 24, 2026, 9:17 a.m. | 1 hour, 30 minutes ago Description :The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-87739 Published : Sept. 24, 2026, 7:16 a.m. | 3 hours, 30 minutes ago Description :An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82077 Published : Sept. 24, 2026, 7:16 a.m. | 3 hours, 30 minutes ago Description :An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11744 Published : Sept. 24, 2026, 7:16 a.m. | 3 hours, 30 minutes ago Description :An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's web view interface. A local attacker with physical access to the device and a specially crafted NFC card or emulator could exploit this flaw to execute arbitrary code within the context of the application's user interface. This could result in unauthorized actions or information disclosure. Severity: 3.8 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97181 Published : Sept. 24, 2026, 8:17 a.m. | 2 hours, 30 minutes ago Description :GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Adobe dicht kritieke kwetsbaarheden in Connect en AEM Forms Adobe heeft beveiligingsupdates uitgebracht voor kritieke kwetsbaarheden in Adobe Connect en Adobe Experience Manager (AEM) Forms. Verschillende beveiligingslekken maken het mogelijk om willekeurige c ... Read more Published Date: Sep 24, 2026 (4 days, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-75745 CVE-2026-75682
Pagina 163 di 3758