News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
45233 risultati
The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
CVE ID :CVE-2026-77193 Published : Sept. 24, 2026, 9:17 a.m. | 1 hour, 30 minutes ago Description :The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-87739 Published : Sept. 24, 2026, 7:16 a.m. | 3 hours, 30 minutes ago Description :An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82077 Published : Sept. 24, 2026, 7:16 a.m. | 3 hours, 30 minutes ago Description :An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11744 Published : Sept. 24, 2026, 7:16 a.m. | 3 hours, 30 minutes ago Description :An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's web view interface. A local attacker with physical access to the device and a specially crafted NFC card or emulator could exploit this flaw to execute arbitrary code within the context of the application's user interface. This could result in unauthorized actions or information disclosure. Severity: 3.8 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97181 Published : Sept. 24, 2026, 8:17 a.m. | 2 hours, 30 minutes ago Description :GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Adobe dicht kritieke kwetsbaarheden in Connect en AEM Forms Adobe heeft beveiligingsupdates uitgebracht voor kritieke kwetsbaarheden in Adobe Connect en Adobe Experience Manager (AEM) Forms. Verschillende beveiligingslekken maken het mogelijk om willekeurige c ... Read more Published Date: Sep 24, 2026 (4 days, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-75745 CVE-2026-75682
CVE ID :CVE-2026-81645 Published : Sept. 24, 2026, 7:16 a.m. | 3 hours, 30 minutes ago Description :Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97176 Published : Sept. 24, 2026, 6:17 a.m. | 4 hours, 30 minutes ago Description :A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97168 Published : Sept. 24, 2026, 6:17 a.m. | 4 hours, 30 minutes ago Description :Rejected reason: suggestion Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97177 Published : Sept. 24, 2026, 6:17 a.m. | 4 hours, 30 minutes ago Description :A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account. Severity: 6.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93662 Published : Sept. 24, 2026, 6:17 a.m. | 4 hours, 30 minutes ago Description :The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 175 di 3770