News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36763 risultati
CVE ID :CVE-2025-68060 Published : May 7, 2026, 9:16 a.m. | 3 hours, 8 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allows Blind SQL Injection. This issue affects Team Member: from n/a through 8.5. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-66105 Published : May 7, 2026, 9:16 a.m. | 3 hours, 8 minutes ago Description :Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-62127 Published : May 7, 2026, 9:16 a.m. | 3 hours, 8 minutes ago Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Slider allows DOM-Based XSS. This issue affects WEN Logo Slider: from n/a through 3.4.0. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.
CVE ID :CVE-2024-43384 Published : May 7, 2026, 9:16 a.m. | 1 hour, 8 minutes ago Description :A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs In a calculated move that signals the expansion of state-sponsored threats into open-source repositories, researchers at Kaspersky Labs have uncovered a sophisticated supply chain attack on PyPI (the ... Read more Published Date: May 07, 2026 (23 hours, 25 minutes ago) Vulnerabilities has been mentioned in this article.
Critical vm2 Node.js Library Vulnerabilities Enables Arbitrary Code Execution Attacks VM2 has been hit by 11 critical vulnerabilities, putting countless applications that rely on it at risk of executing untrusted code. Affecting all versions up to 3.11.1, each flaw provides attackers w ... Read more Published Date: May 07, 2026 (23 hours, 37 minutes ago) Vulnerabilities has been mentioned in this article.
Critical Ollama Memory Leak Vulnerability Exposes 300,000 Servers Globally A major security flaw has placed Ollama, one of the most widely used platforms for running local AI models, at risk of a high-profile exposure event. The issue, dubbed “Bleeding Llama,” allows unauthe ... Read more Published Date: May 07, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-7482
CVE ID :CVE-2026-4430 Published : May 7, 2026, 8:16 a.m. | 2 hours, 9 minutes ago Description :Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-9661 Published : May 7, 2026, 8:16 a.m. | 2 hours, 9 minutes ago Description :OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-44406 Published : May 7, 2026, 8:16 a.m. | 2 hours, 9 minutes ago Description :ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is possible because 'original-file' is a public (non-protected) meta key — it does not begin with an underscore — allowing Authors to freely create or modify it on their own attachment posts via the standard Edit Media form or the REST API.
Pagina 1804 di 3064