Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45178 risultati

VulnerabilitàAlta
CVE-2026-89004 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosure via IDOR

CVE ID :CVE-2026-89004 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-82849 - Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR

CVE ID :CVE-2026-82849 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the requested account is not named with a non-zero value, in which case the records of every learner on the site are returned at once. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-82850 - Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure

CVE ID :CVE-2026-82850 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that hides them is applied only to a fixed list of question types, so the answers to every other type are returned in full to anyone able to view the questions. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-80513 - wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields

CVE ID :CVE-2026-80513 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before 3.1.6 itself; if one is present via another installed wpForo Forum WordPress plugin before 3.1.6 or , this could lead to remote code execution, arbitrary file operations, or SQL injection. This is an incomplete fix of CVE-2026-49769. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-82195 - 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion

CVE ID :CVE-2026-82195 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete it repeatedly, preventing an administrator from completing a legitimate connection. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-84151 - The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-List Widening

CVE ID :CVE-2026-84151 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection (phishing frames, CSS defacement and spoofed input forms) that renders to any visitor and to administrators reviewing the content. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-80338 - CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler

CVE ID :CVE-2026-80338 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break core site settings and take the site offline. Exploitation requires the site's or another CMB2 WordPress plugin before 2.13.0 to have declared an oEmbed field, as the CMB2 WordPress plugin before 2.13.0 registers none of its own. The stored value is never attacker-controlled, so the issue does not lead to privilege escalation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-74991 - WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent

CVE ID :CVE-2026-74991 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the site owner's Stripe account. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-14780 - PaperCut NG/MF: Remote Code Execution via Scripting Subsystem

CVE ID :CVE-2026-14780 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox. A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
News
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could all ... Read more Published Date: Sep 24, 2026 (4 days, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-87902

CVEfeed Newsroom24 set 2026
VulnerabilitàAlta
CVE-2026-97155 - Fabasoft Folio Client Cross-Origin Request Vulnerability

CVE ID :CVE-2026-97155 Published : Sept. 24, 2026, 4:18 a.m. | 2 hours, 32 minutes ago Description :Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default, resulting in all domains being trusted. As a consequence, any website visited by a user with the Folio Client and browser extension installed could invoke client functions, e.g., related to downloading documents, opening documents, and synchronizing files. The first fixed builds are Fabasoft Folio Client 2026 (Build 26.0.0.10) and Fabasoft Folio Client 2026 April Release (Build 26.4.0.76). This client is, for example, shipped with Fabasoft eGov-Suite. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-97152 - Nanomsg WebSocket Transport Buffer Overflow

CVE ID :CVE-2026-97152 Published : Sept. 24, 2026, 4:18 a.m. | 2 hours, 32 minutes ago Description :Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026

Pagina 172 di 3765

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.