News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36321 risultati
CVE ID :CVE-2025-68421 Published : May 14, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elevated privileges including executing system commands on a server. This issue has been fixed in version 2026.4 Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-68420 Published : May 14, 2026, 11:16 a.m. | 1 hour, 14 minutes ago Description :Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the client process to dump it's memory, extract credentials and use them to gain a privileged access to the database. In order to exploit this vulnerability, the client application has to be already configured, but a user does not have to be logged in. This issue has been fixed in version 2026.4 Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerability in simdjson library Vulnerability in simdjson library CVE ID CVE-2026-8295 Publication date 14 May 2026 Vendor simdjson Product simdjson Vulnerable versions All before 4.6.4 Vulnerability type (CWE) Integer Overflow or W ... Read more Published Date: May 14, 2026 (20 hours, 54 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-8295
Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001.
CVE ID :CVE-2026-2347 Published : May 14, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. This issue affects E-Commerce Website: before 4.5.001.
CVE ID :CVE-2025-11024 Published : May 14, 2026, 10:16 a.m. | 2 hours, 14 minutes ago Description :Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. This issue affects E-Commerce Website: before 4.5.001. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Nginx Releases Critical Update: Six Vulnerabilities Patched in New Stable Version The web infrastructure world received a major wake-up call today as nginx-1.30.1 was released to address a suite of six security vulnerabilities. These flaws range from high-severity arbitrary code ex ... Read more Published Date: May 14, 2026 (19 hours, 35 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-2347 CVE-2025-11024 CVE-2026-6512 CVE-2026-6510 CVE-2026-6271 CVE-2026-8181 CVE-2026-45158 CVE-2026-44442 CVE-2026-44194 CVE-2026-44193 CVE-2026-0263 CVE-2026-42946 CVE-2026-42945 CVE-2026-42934 CVE-2026-42926 CVE-2026-40701 CVE-2026-40460 CVE-2026-32661 CVE-2026-6973 CVE-2026-0300 CVE-2026-33636 CVE-2026-33416 CVE-2026-1642 CVE-2025-23419
Critical IKEv2 Buffer Overflow and CAS Bypass Hit Palo Alto PAN-OS Palo Alto Networks has released a series of important security updates addressing multiple vulnerabilities across its PAN-OS software. The most alarming of these is a buffer overflow in IKEv2 processi ... Read more Published Date: May 14, 2026 (20 hours, 10 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-6510 CVE-2026-6271 CVE-2026-8181 CVE-2026-45158 CVE-2026-44442 CVE-2026-44194 CVE-2026-44193 CVE-2026-45714 CVE-2026-45053 CVE-2026-44377 CVE-2026-0265 CVE-2026-0264 CVE-2026-0263 CVE-2026-32661 CVE-2026-6973 CVE-2026-0300 CVE-2026-0229 CVE-2026-0227 CVE-2025-0110 CVE-2025-0108 CVE-2024-5914
Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation An anonymous cybersecurity researcher who disclosed three Microsoft Defender vulnerabilities has returned with two more zero-days involving a BitLocker bypass and a privilege escalation impacting Wind ... Read more Published Date: May 14, 2026 (20 hours, 23 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-23918 CVE-2026-33825 CVE-2025-48804 CVE-2023-24932
The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
CVE ID :CVE-2026-6514 Published : May 14, 2026, 9:16 a.m. | 3 hours, 14 minutes ago Description :The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 1649 di 3027