Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36822 risultati

VulnerabilitàAlta
CVE-2026-27693 - traccar allows XML injection in KML and GPX exports

CVE ID :CVE-2026-27693 Published : May 5, 2026, 1:16 p.m. | 1 hour, 5 minutes ago Description :Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can create a device with a crafted name that injects XML content into exported files. If another user exports and opens the affected KML or GPX file, this can corrupt the file structure and spoof exported location data. This issue is fixed in version 6.13.0. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-28510 - elabftw allows MFA bypass during login

CVE ID :CVE-2026-28510 Published : May 5, 2026, 1:16 p.m. | 1 hour, 5 minutes ago Description :eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an attacker-controlled TOTP secret and bypass the additional factor. This could result in unauthorized account access. This issue is fixed in version 5.4.2. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-30246 - github.com/gofiber/fiber/v3 cache middleware can mix responses across query parameters

CVE ID :CVE-2026-30246 Published : May 5, 2026, 1:16 p.m. | 1 hour, 5 minutes ago Description :Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not include the query string. As a result, requests for the same path with different query parameters can share a cache key and receive the wrong cached response. This can cause response mix-up for query-dependent endpoints and may expose data intended for a different request. This issue is fixed after version 3.1.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-27694 - traccar allows stored HTML injection in notification emails

CVE ID :CVE-2026-27694 Published : May 5, 2026, 1:16 p.m. | 1 hour, 5 minutes ago Description :Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver names into HTML email output without proper escaping. An attacker with low privileges can store crafted HTML in these fields, which is then rendered in notification emails sent to other users with access to the affected devices. This can lead to phishing or spoofed email content. This issue is fixed in version 6.13.0. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-27644 - traccar allows CSV formula injection via exported position data

CVE ID :CVE-2026-27644 Published : May 5, 2026, 1:16 p.m. | 1 hour, 5 minutes ago Description :Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fields. When a manager or administrator opens the exported CSV file in spreadsheet software, this can cause formula execution and lead to command execution or data exfiltration. This has been patched in version 6.13.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-29168 - Apache HTTP Server: mod_md unrestricted OCSP response

CVE ID :CVE-2026-29168 Published : May 5, 2026, 1:10 p.m. | 1 hour, 11 minutes ago Description :Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
News
WhatsApp dicht spoofinglek dat uitvoerbare bestanden kon vermommen

WhatsApp dicht spoofinglek dat uitvoerbare bestanden kon vermommen WhatsApp heeft een spoofinglek in WhatsApp voor Windows gepatcht waardoor het mogelijk was om uitvoerbare bestanden als een ander soort bestand te vermommen. Daarnaast is een beveiligingslek in WhatsA ... Read more Published Date: May 05, 2026 (1 day, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-23866 CVE-2026-23863

CVEfeed Newsroom05 mag 2026
VulnerabilitàAlta
CVE-2026-6261 (CVSS 8.8)

The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directory without validating extracted file types. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files (including PHP) and achieve remote code execution via the Icons icon-pack upload flow.

NVD (NIST)05 mag 2026
VulnerabilitàAlta
CVE-2026-43573 (CVSS 7.7)

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with or navigate to unauthorized targets without policy enforcement.

NVD (NIST)05 mag 2026
VulnerabilitàAlta
CVE-2026-43573 - OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction Routes

CVE ID :CVE-2026-43573 Published : May 5, 2026, 12:16 p.m. | 2 hours, 5 minutes ago Description :OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with or navigate to unauthorized targets without policy enforcement. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-6261 - Betheme <= 28.4 - Authenticated (Author+) Arbitrary File Upload to Remote Code Execution via Icon Pack Upload

CVE ID :CVE-2026-6261 Published : May 5, 2026, 12:16 p.m. | 2 hours, 5 minutes ago Description :The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directory without validating extracted file types. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files (including PHP) and achieve remote code execution via the Icons icon-pack upload flow. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-43571 (CVSS 8.8)

OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace plugins that bypass intended trust gates during setup-time plugin loading.

NVD (NIST)05 mag 2026

Pagina 1839 di 3069

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.