Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

VulnerabilitàAlta
CVE-2024-33724 - SOPlanning Cross Site Scripting (XSS)

CVE ID :CVE-2024-33724 Published : May 8, 2026, 6:16 a.m. | 2 hours, 9 minutes ago Description :SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2024-30167 - Atlona AT-OME-MS42 Remote Command Execution Vulnerability

CVE ID :CVE-2024-30167 Published : May 8, 2026, 6:16 a.m. | 2 hours, 9 minutes ago Description :/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2024-33288 - "PHP Prison Management System SQL Injection"

CVE ID :CVE-2024-33288 Published : May 8, 2026, 6:16 a.m. | 2 hours, 9 minutes ago Description :Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2024-33722 - SOPlanning SQL Injection

CVE ID :CVE-2024-33722 Published : May 8, 2026, 6:16 a.m. | 2 hours, 9 minutes ago Description :SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[]. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2026-8148 - NAVER MYBOX Explorer Windows Privilege Escalation Vulnerability

CVE ID :CVE-2026-8148 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2026-8138 (CVSS 8.8)

A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

NVD (NIST)08 mag 2026
VulnerabilitàAlta
CVE-2026-8137 (CVSS 8.8)

A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

NVD (NIST)08 mag 2026
VulnerabilitàAlta
CVE-2026-8137 - Totolink X5000R formDdns sub_458E40 buffer overflow

CVE ID :CVE-2026-8137 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2026-8138 - Tenda CX12L SetPptpServerCfg” formSetPPTPServer stack-based overflow

CVE ID :CVE-2026-8138 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2026-42279 - solidtime: Time entry update endpoint allows cross-organization modification of a known time-entry UUID

CVE ID :CVE-2026-42279 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a route-bound timeEntry from another organization when the caller has time-entries:update:all in the URL organization, allowing a known foreign time-entry UUID to be modified and rebound to objects in the caller's organization. This issue has been patched in version 0.12.1. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2026-42277 - Onyx: IDOR in /chat/file/{file_id} allows any authenticated user to download other users files

CVE ID :CVE-2026-42277 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other user's uploaded files by providing the file UUID. The endpoint verifies the caller is authenticated but never checks that the file belongs to them. An attacker who knows or obtains a file UUID can access confidential documents, chat attachments, and other files uploaded by any user in the system. This issue has been patched in versions 3.0.9, 3.1.6, and 3.2.6. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026
VulnerabilitàAlta
CVE-2026-42276 - Onyx: IDOR in /chat/stop-chat-session allows any authenticated user to interrupt other users chat sessions

CVE ID :CVE-2026-42276 Published : May 8, 2026, 5:16 a.m. | 1 hour, 9 minutes ago Description :Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active chat session. The endpoint checks authentication but never verifies the session belongs to the caller. An attacker who knows a chat session UUID can kill another user's LLM generation mid-stream. This issue has been patched in versions 3.0.9, 3.1.6, and 3.2.6. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 mag 2026

Pagina 1784 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.