Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45120 risultati

VulnerabilitàAlta
CVE-2026-97181 - ezGlobal|GPM LIGHT - Sensitive Data Exposure

CVE ID :CVE-2026-97181 Published : Sept. 24, 2026, 8:17 a.m. | 2 hours, 30 minutes ago Description :GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
News
Adobe dicht kritieke kwetsbaarheden in Connect en AEM Forms

Adobe dicht kritieke kwetsbaarheden in Connect en AEM Forms Adobe heeft beveiligingsupdates uitgebracht voor kritieke kwetsbaarheden in Adobe Connect en Adobe Experience Manager (AEM) Forms. Verschillende beveiligingslekken maken het mogelijk om willekeurige c ... Read more Published Date: Sep 24, 2026 (4 days, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-75745 CVE-2026-75682

CVEfeed Newsroom24 set 2026
VulnerabilitàAlta
CVE-2026-81645 - Graphics Module Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-81645 Published : Sept. 24, 2026, 7:16 a.m. | 3 hours, 30 minutes ago Description :Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-97177 - Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission

CVE ID :CVE-2026-97177 Published : Sept. 24, 2026, 6:17 a.m. | 4 hours, 30 minutes ago Description :A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account. Severity: 6.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-93662 - Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via 'owner' Parameter

CVE ID :CVE-2026-93662 Published : Sept. 24, 2026, 6:17 a.m. | 4 hours, 30 minutes ago Description :The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-97168 - Rejected reason: suggestion

CVE ID :CVE-2026-97168 Published : Sept. 24, 2026, 6:17 a.m. | 4 hours, 30 minutes ago Description :Rejected reason: suggestion Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-97176 - Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator

CVE ID :CVE-2026-97176 Published : Sept. 24, 2026, 6:17 a.m. | 4 hours, 30 minutes ago Description :A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-93661 - Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR

CVE ID :CVE-2026-93661 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-89005 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category

CVE ID :CVE-2026-89005 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any higher-privileged user who later views the campaign. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-89002 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview

CVE ID :CVE-2026-89002 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Scripting attacks against higher-privileged users who review the campaign. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-89004 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosure via IDOR

CVE ID :CVE-2026-89004 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-88843 - MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widget

CVE ID :CVE-2026-88843 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute arbitrary local PHP files on the server. An equivalent path was corrected in an earlier release and this one was not, so the issue persists in versions the earlier advisory reports as fixed. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026

Pagina 166 di 3760

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.