Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36737 risultati

VulnerabilitàAlta
CVE-2022-50964 - uBidAuction 2.0.1 myAuctions loose Reflected XSS

CVE ID :CVE-2022-50964 Published : May 10, 2026, 1:16 p.m. | 11 hours, 13 minutes ago Description :uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50967 - uBidAuction 2.0.1 tickets manage Reflected XSS

CVE ID :CVE-2022-50967 Published : May 10, 2026, 1:16 p.m. | 13 hours, 13 minutes ago Description :uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the tickets/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50969 - uBidAuction 2.0.1 mailingLog manage Reflected XSS

CVE ID :CVE-2022-50969 Published : May 10, 2026, 1:16 p.m. | 13 hours, 13 minutes ago Description :uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the backend/mailingLog/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50963 - uBidAuction 2.0.1 myAuctions active Reflected XSS

CVE ID :CVE-2022-50963 Published : May 10, 2026, 1:16 p.m. | 11 hours, 13 minutes ago Description :uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/active module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50966 - uBidAuction 2.0.1 news manage Reflected XSS

CVE ID :CVE-2022-50966 Published : May 10, 2026, 1:16 p.m. | 11 hours, 13 minutes ago Description :uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the news/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50970 - WordPress Plugin AAWP 3.16 Reflected XSS via tab Parameter

CVE ID :CVE-2022-50970 Published : May 10, 2026, 1:16 p.m. | 13 hours, 13 minutes ago Description :WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the tab parameter. Attackers can craft URLs with XSS payloads in the tab parameter of the aawp-settings admin page to execute arbitrary JavaScript in the context of authenticated users. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50965 - uBidAuction 2.0.1 posts manage Reflected XSS

CVE ID :CVE-2022-50965 Published : May 10, 2026, 1:16 p.m. | 11 hours, 13 minutes ago Description :uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50968 - uBidAuction 2.0.1 auctions manage Reflected XSS

CVE ID :CVE-2022-50968 Published : May 10, 2026, 1:16 p.m. | 13 hours, 13 minutes ago Description :uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50957 - Drupal avatar_uploader 7.x-1.0-beta8 Reflected XSS

CVE ID :CVE-2022-50957 Published : May 10, 2026, 1:16 p.m. | 9 hours, 13 minutes ago Description :Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execute arbitrary JavaScript in victim browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50956 - WordPress Plugin amministrazione-aperta 3.7.3 Local File Read

CVE ID :CVE-2022-50956 Published : May 10, 2026, 1:16 p.m. | 9 hours, 13 minutes ago Description :WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter in dispatcher.php to include and read sensitive files accessible to the web server. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50962 - uBidAuction 2.0.1 myOrders Reflected XSS

CVE ID :CVE-2022-50962 Published : May 10, 2026, 1:16 p.m. | 11 hours, 13 minutes ago Description :uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2022-50961 - WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS

CVE ID :CVE-2022-50961 Published : May 10, 2026, 1:16 p.m. | 11 hours, 13 minutes ago Description :WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when administrators or other authenticated users visit the plugin settings page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026

Pagina 1755 di 3062

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.