Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36308 risultati

VulnerabilitàAlta
CVE-2026-4029 - Database Backup for WordPress <= 2.5.2 - Missing Authorization to Unauthenticated Database Export

CVE ID :CVE-2026-4029 Published : May 14, 2026, 1:16 p.m. | 1 hour, 14 minutes ago Description :The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables, leading to Sensitive Information Exposure. Note: This vulnerability is only exploitable in WordPress Multisite environments where the deprecated is_site_admin() function exists. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2026-43644 - podinfo 6.11.2 Reflected XSS via /echo Endpoint

CVE ID :CVE-2026-43644 Published : May 14, 2026, 1:16 p.m. | 1 hour, 14 minutes ago Description :podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without setting explicit Content-Type or X-Content-Type-Options headers. Attackers can craft cross-origin HTML pages with auto-submitting forms containing script payloads in the request body, which are served as text/html due to Go's content type detection, allowing the reflected script to execute in the podinfo origin context when victims visit the attacker's page. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2025-12008 (CVSS 8.8)

Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Yaay Social Media App: from 3.8.0 through 24102025.

NVD (NIST)14 mag 2026
VulnerabilitàAlta
CVE-2025-12008 - IDOR in APPYAP's Yaay Social Media App

CVE ID :CVE-2025-12008 Published : May 14, 2026, 1:16 p.m. | 1 hour, 14 minutes ago Description :Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Yaay Social Media App: from 3.8.0 through 24102025. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
News
Vulnerabilities in Comarch ERP Optima software

Vulnerabilities in Comarch ERP Optima software Vulnerabilities in Comarch ERP Optima software CVE ID CVE-2025-68420 Publication date 14 May 2026 Vendor Comarch Product ERP Optima Vulnerable versions All before 2026.4 Vulnerability type (CWE) Incor ... Read more Published Date: May 14, 2026 (18 hours, 54 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-68421 CVE-2025-68420

CVEfeed Newsroom14 mag 2026
News
Critical GitLab Vulnerabilities Enables XSS and Unauthenticated DoS Attacks

Critical GitLab Vulnerabilities Enables XSS and Unauthenticated DoS Attacks Threat actors are constantly hunting for infrastructure weaknesses, and a newly discovered batch of vulnerabilities in GitLab just handed them a dangerous roadmap. On May 13, 2026, GitLab rolled out e ... Read more Published Date: May 14, 2026 (19 hours, 23 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom14 mag 2026
VulnerabilitàAlta
CVE-2026-45205 - Apache Commons Configuration: StackOverflowError for YAML input with cycles

CVE ID :CVE-2026-45205 Published : May 14, 2026, 12:16 p.m. | 2 hours, 14 minutes ago Description :Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
News
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours of public disclos ... Read more Published Date: May 14, 2026 (20 hours, 9 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-44338 CVE-2026-23918

CVEfeed Newsroom14 mag 2026
News
Palo Alto PAN-OS 0-Day Exploited to Execute Arbitrary Code With Root Privileges on Firewalls

Palo Alto PAN-OS 0-Day Exploited to Execute Arbitrary Code With Root Privileges on Firewalls A critical vulnerability in Palo Alto Networks PAN-OS is putting enterprise firewalls at risk, allowing unauthenticated attackers to execute arbitrary code with root privileges. Tracked as CVE-2026-03 ... Read more Published Date: May 14, 2026 (20 hours, 22 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-0300 CVE-2026-33017

CVEfeed Newsroom14 mag 2026
VulnerabilitàAlta
CVE-2026-8468 - Unbounded buffer accumulation in multipart header parsing causes denial of service in plug

CVE ID :CVE-2026-8468 Published : May 14, 2026, 11:16 a.m. | 3 hours, 14 minutes ago Description :Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in lib/plug/conn.ex does not obey its :length parameter. There is no upper bound on the size of the accumulated buffer. By contrast, the sibling function read_part_body has an explicit byte_size(acc) > length guard that stops accumulation once a limit is reached. No such guard exists in read_part_headers. An unauthenticated remote attacker can exhaust server memory by sending a crafted multipart/form-data request, causing a denial of service. This issue affects plug from 1.4.0 before 1.15.4, 1.16.3, 1.17.1, 1.18.2, and 1.19.2. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2026-8295 - Integer overflow in simdjson

CVE ID :CVE-2026-8295 Published : May 14, 2026, 11:16 a.m. | 3 hours, 14 minutes ago Description :An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_append()" when processing very large input strings on platforms with limited "size_t" width (e.g., 32-bit builds). The overflow can cause insufficient buffer allocation, leading to out-of-bounds memory reads in SIMD routines and potentially resulting in information disclosure, memory corruption, or malformed JSON output. This vulnerability has been fixed in 4.6.4 release Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàAlta
CVE-2025-68421 - Hardcoded credentials in Comarch ERP Optima

CVE ID :CVE-2025-68421 Published : May 14, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server. This issue has been fixed in version 2026.4 Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026

Pagina 1647 di 3026

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.