Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36462 risultati

VulnerabilitàAlta
CVE-2025-9988 - Broadstreet <= 1.53.1 - Missing Authorization to Authenticated (Subscriber+) Advertiser Creation

CVE ID :CVE-2025-9988 Published : May 13, 2026, 4:26 a.m. | 2 hours, 4 minutes ago Description :The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create advertisers. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
News
GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping

GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping Security researchers are sounding the alarm on a highly resourceful new campaign dubbed “GemStuffer.” Uncovered by Socket’s threat research team, this operation involves more than 100 packages that ex ... Read more Published Date: May 13, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
VulnerabilitàAlta
CVE-2025-14755 - Cost Calculator Builder <= 4.0.1 - Unauthenticated Price Manipulation and Insecure Direct Object Reference

CVE ID :CVE-2025-14755 Published : May 13, 2026, 3:26 a.m. | 3 hours, 4 minutes ago Description :The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR) in all versions up to, and including, 4.0.1 only when used in combination with Cost Calculator Builder PRO. This is due to the ccb_woocommerce_payment AJAX action being registered via wp_ajax_nopriv, making it accessible to unauthenticated users, and the renderWooCommercePayment() function passing user-controlled data directly to CCBWooCheckout::init() without authorization checks. This makes it possible for unauthenticated attackers to add WooCommerce products to their cart with attacker-controlled prices. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-6888 - SQL Injection Vulnerability

CVE ID :CVE-2026-6888 Published : May 13, 2026, 3:16 a.m. | 3 hours, 14 minutes ago Description :Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2024-36315 - Intel x86 CPU Speculative Execution Information Disclosure Vulnerability

CVE ID :CVE-2024-36315 Published : May 13, 2026, 3:07 a.m. | 1 hour, 23 minutes ago Description :Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensitive information, potentially resulting in loss of confidentiality. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2025-61972 - AMD Secure Processor ASP Unprivileged SMN Code Execution

CVE ID :CVE-2025-61972 Published : May 13, 2026, 3:03 a.m. | 1 hour, 27 minutes ago Description :Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2025-61971 - AMD SEV-SNP MMIO Routing Configuration Modification Vulnerability

CVE ID :CVE-2025-61971 Published : May 13, 2026, 3:02 a.m. | 1 hour, 27 minutes ago Description :Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing configurations, potentially resulting in loss of SEV-SNP guest integrity. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2025-62627 - VMware ESXi Pointer Dereference Vulnerability

CVE ID :CVE-2025-62627 Published : May 13, 2026, 2:59 a.m. | 1 hour, 31 minutes ago Description :An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2025-62624 - VMware ESXi Heap-Based Buffer Overflow Vulnerability

CVE ID :CVE-2025-62624 Published : May 13, 2026, 2:58 a.m. | 1 hour, 32 minutes ago Description :A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2025-62623 - VMware ESXi Heap-Based Buffer Overflow Privilege Escalation

CVE ID :CVE-2025-62623 Published : May 13, 2026, 2:58 a.m. | 1 hour, 32 minutes ago Description :A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
News
Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks

Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks A newly disclosed security vulnerability in Microsoft Teams could allow attackers to spoof local devices, raising concerns for enterprises and individual users who rely on the platform for daily commu ... Read more Published Date: May 13, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32185

CVEfeed Newsroom13 mag 2026
News
Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers

Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers Siemens ProductCERT issued an urgent security advisory regarding multiple Cross-Site Scripting (XSS) vulnerabilities found within the web servers of its powerhouse SIMATIC S7 PLC lineup. With CVSS v4. ... Read more Published Date: May 13, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026

Pagina 1685 di 3039

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.