Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36308 risultati

VulnerabilitàAlta
CVE-2025-68420 - Privilege Escalation in Comarch ERP Optima

CVE ID :CVE-2025-68420 Published : May 14, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the client process to dump it's memory, extract credentials and use them to gain a privileged access to the database. In order to exploit this vulnerability, the client application has to be already configured, but a user does not have to be logged in. This issue has been fixed in version 2026.4 Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
News
Vulnerability in simdjson library

Vulnerability in simdjson library Vulnerability in simdjson library CVE ID CVE-2026-8295 Publication date 14 May 2026 Vendor simdjson Product simdjson Vulnerable versions All before 4.6.4 Vulnerability type (CWE) Integer Overflow or W ... Read more Published Date: May 14, 2026 (20 hours, 54 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-8295

CVEfeed Newsroom14 mag 2026
VulnerabilitàCritica
CVE-2026-2347 (CVSS 9.8)

Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001.

NVD (NIST)14 mag 2026
VulnerabilitàAlta
CVE-2026-2347 - IDOR in Akıllı Ticaret's E-Commerce Pack

CVE ID :CVE-2026-2347 Published : May 14, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàCritica
CVE-2025-11024 (CVSS 9.8)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. This issue affects E-Commerce Website: before 4.5.001.

NVD (NIST)14 mag 2026
VulnerabilitàAlta
CVE-2025-11024 - SQLi in Akıllı Ticaret's E-Commerce Pack

CVE ID :CVE-2025-11024 Published : May 14, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. This issue affects E-Commerce Website: before 4.5.001. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
News
Nginx Releases Critical Update: Six Vulnerabilities Patched in New Stable Version

Nginx Releases Critical Update: Six Vulnerabilities Patched in New Stable Version The web infrastructure world received a major wake-up call today as nginx-1.30.1 was released to address a suite of six security vulnerabilities. These flaws range from high-severity arbitrary code ex ... Read more Published Date: May 14, 2026 (19 hours, 35 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-2347 CVE-2025-11024 CVE-2026-6512 CVE-2026-6510 CVE-2026-6271 CVE-2026-8181 CVE-2026-45158 CVE-2026-44442 CVE-2026-44194 CVE-2026-44193 CVE-2026-0263 CVE-2026-42946 CVE-2026-42945 CVE-2026-42934 CVE-2026-42926 CVE-2026-40701 CVE-2026-40460 CVE-2026-32661 CVE-2026-6973 CVE-2026-0300 CVE-2026-33636 CVE-2026-33416 CVE-2026-1642 CVE-2025-23419

CVEfeed Newsroom14 mag 2026
News
Critical IKEv2 Buffer Overflow and CAS Bypass Hit Palo Alto PAN-OS

Critical IKEv2 Buffer Overflow and CAS Bypass Hit Palo Alto PAN-OS Palo Alto Networks has released a series of important security updates addressing multiple vulnerabilities across its PAN-OS software. The most alarming of these is a buffer overflow in IKEv2 processi ... Read more Published Date: May 14, 2026 (20 hours, 10 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-6510 CVE-2026-6271 CVE-2026-8181 CVE-2026-45158 CVE-2026-44442 CVE-2026-44194 CVE-2026-44193 CVE-2026-45714 CVE-2026-45053 CVE-2026-44377 CVE-2026-0265 CVE-2026-0264 CVE-2026-0263 CVE-2026-32661 CVE-2026-6973 CVE-2026-0300 CVE-2026-0229 CVE-2026-0227 CVE-2025-0110 CVE-2025-0108 CVE-2024-5914

CVEfeed Newsroom14 mag 2026
News
Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation

Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation An anonymous cybersecurity researcher who disclosed three Microsoft Defender vulnerabilities has returned with two more zero-days involving a BitLocker bypass and a privilege escalation impacting Wind ... Read more Published Date: May 14, 2026 (20 hours, 23 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-23918 CVE-2026-33825 CVE-2025-48804 CVE-2023-24932

CVEfeed Newsroom14 mag 2026
VulnerabilitàAlta
CVE-2026-6514 (CVSS 7.5)

The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

NVD (NIST)14 mag 2026
VulnerabilitàAlta
CVE-2026-6514 - InfusedWoo Pro <= 5.1.2 - Unauthenticated Arbitrary File Read via 'url' Parameter

CVE ID :CVE-2026-6514 Published : May 14, 2026, 9:16 a.m. | 3 hours, 14 minutes ago Description :The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 mag 2026
VulnerabilitàCritica
CVE-2026-6512 (CVSS 9.1)

The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or orders, mass-delete all comments on any post, and change any post's status.

NVD (NIST)14 mag 2026

Pagina 1648 di 3026

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.