Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36437 risultati

VulnerabilitàAlta
CVE-2026-25107 - ELECOM Wireless LAN Access Point Device Cryptographic Key Weakness

CVE ID :CVE-2026-25107 Published : May 13, 2026, 12:01 p.m. | 2 hours, 29 minutes ago Description :ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
News
Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws Microsoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active attack. Of the 138 flaws ... Read more Published Date: May 13, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
News
Critical SandboxJS Escape Vulnerability Enables Host Takeover

Critical SandboxJS Escape Vulnerability Enables Host Takeover A critical security flaw has been found in SandboxJS, a widely used JavaScript sandboxing library available on npm. The vulnerability allows attackers to break out of the sandbox entirely and run any ... Read more Published Date: May 13, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
VulnerabilitàAlta
CVE-2026-4782 - Avada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter

CVE ID :CVE-2026-4782 Published : May 13, 2026, 9:26 a.m. | 5 hours, 4 minutes ago Description :The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the 'fusion_get_svg_from_file' function with the 'custom_svg' parameter of the 'fusion_section_separator' shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability was partially patched in version 3.15.2 and fully patched in version 3.15.3. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-4798 - Avada Builder <= 3.15.1 - Unauthenticated SQL Injection via 'product_order' Parameter

CVE ID :CVE-2026-4798 Published : May 13, 2026, 9:26 a.m. | 5 hours, 4 minutes ago Description :The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note: The vulnerability can only be exploited if WooCommerce was previously used and then deactivated. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-25710 - Plasma Loginauth Helper Privilege Escalation Vulnerability

CVE ID :CVE-2026-25710 Published : May 13, 2026, 8:44 a.m. | 5 hours, 46 minutes ago Description :The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the system. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-41051 - csync2 uses insecure temporary directories when compiled with C99 or later

CVE ID :CVE-2026-41051 Published : May 13, 2026, 8:37 a.m. | 5 hours, 53 minutes ago Description :csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2024-47091 - Privilege escalation via mk_mysql agent plugin on Windows

CVE ID :CVE-2024-47091 Published : May 13, 2026, 8:35 a.m. | 5 hours, 55 minutes ago Description :Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-44931 - malcontent: Disk Space Exhaustion via Globally Accessible D-Bus API

CVE ID :CVE-2026-44931 Published : May 13, 2026, 8:30 a.m. | 6 hours ago Description :The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-service.c in malcontent-timerd allows arbitrary users in the system to slowly fill up disk space in /var/lib/malcontent-timerd Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-7168 - cross-proxy Digest auth state leak

CVE ID :CVE-2026-7168 Published : May 13, 2026, 8:29 a.m. | 6 hours, 1 minute ago Description :Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-7009 - OCSP stapling bypass with Apple SecTrust

CVE ID :CVE-2026-7009 Published : May 13, 2026, 8:28 a.m. | 6 hours, 2 minutes ago Description :When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-6429 - netrc credential leak with reused proxy connection

CVE ID :CVE-2026-6429 Published : May 13, 2026, 8:28 a.m. | 4 hours, 2 minutes ago Description :When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026

Pagina 1679 di 3037

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.