Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

VulnerabilitàAlta
CVE-2025-68060 - WordPress Team Member plugin <= 8.5 - SQL Injection vulnerability

CVE ID :CVE-2025-68060 Published : May 7, 2026, 9:16 a.m. | 3 hours, 8 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allows Blind SQL Injection. This issue affects Team Member: from n/a through 8.5. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2025-66105 - WordPress Bus Ticket Booking with Seat Reservation plugin < 5.6.8 - Broken Access Control vulnerability

CVE ID :CVE-2025-66105 Published : May 7, 2026, 9:16 a.m. | 3 hours, 8 minutes ago Description :Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2025-62127 - WordPress WEN Logo Slider plugin <= 3.4.0 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2025-62127 Published : May 7, 2026, 9:16 a.m. | 3 hours, 8 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Slider allows DOM-Based XSS. This issue affects WEN Logo Slider: from n/a through 3.4.0. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2024-43384 (CVSS 8)

A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2024-43384 - Phoenix Contact: Improper removal of sensitive information in MGUARD products

CVE ID :CVE-2024-43384 Published : May 7, 2026, 9:16 a.m. | 1 hour, 8 minutes ago Description :A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
News
OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs

OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs In a calculated move that signals the expansion of state-sponsored threats into open-source repositories, researchers at Kaspersky Labs have uncovered a sophisticated supply chain attack on PyPI (the ... Read more Published Date: May 07, 2026 (23 hours, 25 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
News
Critical vm2 Node.js Library Vulnerabilities Enables Arbitrary Code Execution Attacks

Critical vm2 Node.js Library Vulnerabilities Enables Arbitrary Code Execution Attacks VM2 has been hit by 11 critical vulnerabilities, putting countless applications that rely on it at risk of executing untrusted code. Affecting all versions up to 3.11.1, each flaw provides attackers w ... Read more Published Date: May 07, 2026 (23 hours, 37 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom07 mag 2026
News
Critical Ollama Memory Leak Vulnerability Exposes 300,000 Servers Globally

Critical Ollama Memory Leak Vulnerability Exposes 300,000 Servers Globally A major security flaw has placed Ollama, one of the most widely used platforms for running local AI models, at risk of a high-profile exposure event. The issue, dubbed “Bleeding Llama,” allows unauthe ... Read more Published Date: May 07, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-7482

CVEfeed Newsroom07 mag 2026
VulnerabilitàAlta
CVE-2026-4430 - Heap Buffer Overflow in AgileEngine

CVE ID :CVE-2026-4430 Published : May 7, 2026, 8:16 a.m. | 2 hours, 9 minutes ago Description :Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2025-9661 - OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23/24/26/28

CVE ID :CVE-2025-9661 Published : May 7, 2026, 8:16 a.m. | 2 hours, 9 minutes ago Description :OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-44406 - DLL Hijacking Vulnerability in ZTE Cloud PC Client uSmartview

CVE ID :CVE-2026-44406 Published : May 7, 2026, 8:16 a.m. | 2 hours, 9 minutes ago Description :ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-7252 (CVSS 8.1)

The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is possible because 'original-file' is a public (non-protected) meta key — it does not begin with an underscore — allowing Authors to freely create or modify it on their own attachment posts via the standard Edit Media form or the REST API.

NVD (NIST)07 mag 2026

Pagina 1804 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.