Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36737 risultati

VulnerabilitàAlta
CVE-2021-47935 (CVSS 8.8)

Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with base64-encoded compressed pickle payloads in the data field to achieve code execution with application privileges.

NVD (NIST)10 mag 2026
VulnerabilitàCritica
CVE-2021-47933 (CVSS 9.8)

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server.

NVD (NIST)10 mag 2026
VulnerabilitàCritica
CVE-2021-47932 (CVSS 9.8)

WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to the tcp_register_and_login_ajax action with tcp_role set to administrator to gain full administrative access without authentication.

NVD (NIST)10 mag 2026
VulnerabilitàAlta
CVE-2021-47930 (CVSS 8.2)

Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information.

NVD (NIST)10 mag 2026
VulnerabilitàAlta
CVE-2021-47928 (CVSS 8.2)

Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id parameter. Attackers can craft malicious SQL queries using time-based or content-based blind injection techniques to enumerate usernames, emails, and password reset codes from the oc_user table.

NVD (NIST)10 mag 2026
VulnerabilitàCritica
CVE-2021-47923 (CVSS 9.8)

OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts and maintains, enabling session takeover and unauthorized access to user accounts.

NVD (NIST)10 mag 2026
News
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated attacker to leak its entire process memory. ... Read more Published Date: May 10, 2026 (1 day, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-23918 CVE-2026-7482 CVE-2026-42249 CVE-2026-42248

CVEfeed Newsroom10 mag 2026
News
Zero Installation, Total Compromise: Critical Grav CMS Exploit Chain Grants Unauthenticated RCE

Zero Installation, Total Compromise: Critical Grav CMS Exploit Chain Grants Unauthenticated RCE Grav, the widely used flat-file content management system, disclosures two highly critical vulnerabilities. The platform, celebrated for requiring “Zero installation” and offering a “powerful Package ... Read more Published Date: May 10, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom10 mag 2026
News
Nieuw beveiligingslek in cPanel en WHM laat aanvaller Perl-code uitvoeren

Nieuw beveiligingslek in cPanel en WHM laat aanvaller Perl-code uitvoeren Een nieuw beveiligingslek in cPanel en WHM maakt het mogelijk voor een geauthenticeerde aanvaller om willekeurige Perl-code op de onderliggende machine uit te voeren. Er zijn updates beschikbaar gemaa ... Read more Published Date: May 10, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-29202 CVE-2026-41940

CVEfeed Newsroom10 mag 2026
VulnerabilitàAlta
CVE-2026-8244 - Industrial Application Software IAS Canias ERP Login RMI improper authentication

CVE ID :CVE-2026-8244 Published : May 10, 2026, 10:16 a.m. | 2 hours, 13 minutes ago Description :A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI Interface. The manipulation of the argument clientVersion leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-8243 - Industrial Application Software IAS Canias ERP JNLP Deployment Endpoint hard-coded key

CVE ID :CVE-2026-8243 Published : May 10, 2026, 9:16 a.m. | 3 hours, 13 minutes ago Description :A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026
VulnerabilitàAlta
CVE-2026-8242 - Industrial Application Software IAS Canias ERP Login RMI doAction response discrepancy

CVE ID :CVE-2026-8242 Published : May 10, 2026, 9:16 a.m. | 3 hours, 13 minutes ago Description :A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 mag 2026

Pagina 1758 di 3062

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.