Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36796 risultati

VulnerabilitàAlta
CVE-2026-6344 - Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment

CVE ID :CVE-2026-6344 Published : May 6, 2026, 8:16 a.m. | 2 hours, 7 minutes ago Description :The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without verifying that the resolved path stays inside the WordPress uploads directory: a strpos() prefix check on the raw URL can be bypassed with traversal sequences, wp_normalize_path() does not resolve ".\..\" segments, and file_exists() then resolves them at the kernel level. This makes it possible for authenticated attackers with administrator access to read arbitrary files readable by the web-server user — including wp-config.php with its database credentials and authentication salts — by submitting a form whose admin notification is configured to attach a file-upload field and supplying a crafted URL of the shape /../../ as the file-field value. The resolved file is attached to the outbound admin-notification email via wp_mail(). While the email can be triggered by unauthenticated users, the email recipient is not user-controlled. Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026
VulnerabilitàAlta
CVE-2026-35253 - Oracle Macaron Tool HTTP Host Address Validation Bypass

CVE ID :CVE-2026-35253 Published : May 6, 2026, 8:16 a.m. | 2 hours, 7 minutes ago Description :Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected is v0.22.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Macaron Tool. Successful attacks of this vulnerability can result in Oracle Macaron Tool failing host address validation. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026
News
Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution Palo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the wild. The vulnerability, tracked as CVE-2026-0300, ha ... Read more Published Date: May 06, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom06 mag 2026
VulnerabilitàAlta
CVE-2026-2306 - Ninja Tables <= 5.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Table Creation

CVE ID :CVE-2026-2306 Published : May 6, 2026, 6:16 a.m. | 2 hours, 6 minutes ago Description :The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all versions up to, and including, 5.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary Ninja Tables in the database which can lead to database pollution and resource exhaustion. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026
VulnerabilitàAlta
CVE-2026-5753 - All-in-One WP Migration Unlimited Extension <= 2.83 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Backup Schedule Creation and Backup File Download

CVE ID :CVE-2026-5753 Published : May 6, 2026, 4:16 a.m. | 4 hours, 6 minutes ago Description :The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before saving schedule data. This makes it possible for authenticated attackers, with subscriber-level access and above, to create scheduled export jobs and send backup notifications to attacker-controlled email addresses. Because such notifications include the random backup filename, full site backups can subsequently be downloaded from the target site, resulting in sensitive information exposure. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026
VulnerabilitàAlta
CVE-2026-3208 - Mercado Pago payments for WooCommerce <= 8.7.11 - Missing Authorization to Unauthenticated PIX Payment QR Code Image Disclosure

CVE ID :CVE-2026-3208 Published : May 6, 2026, 4:16 a.m. | 4 hours, 6 minutes ago Description :The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieve PIX payment QR code images for arbitrary orders. PIX QR codes contain sensitive merchant information including PIX keys (which may be CPF/CNPJ personal identifiers), transaction amounts, merchant name and city, and MercadoPago transaction references. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026
VulnerabilitàAlta
CVE-2026-7573 - GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations

CVE ID :CVE-2026-7573 Published : May 6, 2026, 3:15 a.m. | 5 hours, 7 minutes ago Description :An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parameters via a network request. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026
VulnerabilitàAlta
CVE-2026-7572 - Velociraptor EVTX Parser — Process Crash via Crafted .evtx File

CVE ID :CVE-2026-7572 Published : May 6, 2026, 3:15 a.m. | 5 hours, 7 minutes ago Description :An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx VQL plugin. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026
News
Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access

Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access Palo Alto Networks has disclosed a critical buffer overflow vulnerability in PAN-OS software, tracked as CVE-2026-0300, that is already being actively exploited in the wild. The flaw carries a CVSS 4. ... Read more Published Date: May 06, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom06 mag 2026
News
Nix Vulnerability Grants Root Access via NAR Parser Overflow

Nix Vulnerability Grants Root Access via NAR Parser Overflow Nix, the robust package manager celebrated for bringing reliability and reproducibility to Linux and Unix systems, has issued a high-priority security fix for a dangerous memory corruption vulnerabili ... Read more Published Date: May 06, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom06 mag 2026
News
GitOps Security Breach: Critical 9.6 CVSS Argo CD Flaw Exposes Plaintext Kubernetes Secrets

GitOps Security Breach: Critical 9.6 CVSS Argo CD Flaw Exposes Plaintext Kubernetes Secrets Argo CD, the leading GitOps continuous delivery tool for Kubernetes, has issued a high-priority patch for a critical vulnerability that allows read-only users to extract plaintext secrets from the hea ... Read more Published Date: May 06, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom06 mag 2026
VulnerabilitàAlta
CVE-2025-71256 - "NR Modem Remote Denial of Service (DoS) Vulnerability"

CVE ID :CVE-2025-71256 Published : May 6, 2026, 2:16 a.m. | 6 hours, 6 minutes ago Description :In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE06 mag 2026

Pagina 1827 di 3067

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.