Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36827 risultati

VulnerabilitàAlta
CVE-2026-43567 - OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath Parameter

CVE ID :CVE-2026-43567 Published : May 5, 2026, 12:16 p.m. | 2 hours, 5 minutes ago Description :OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying an outPath outside the workspace boundary to write files to unintended locations on the system. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-43535 - OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue Batches

CVE ID :CVE-2026-43535 Published : May 5, 2026, 12:16 p.m. | 2 hours, 5 minutes ago Description :OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different senders to inherit the final sender's authorization context. Attackers can exploit this by sending multiple queued messages to drain batches using a more privileged sender's context, causing earlier messages to execute with elevated permissions. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-43529 - OpenClaw < 2026.4.10 - Time-of-Check-Time-of-Use (TOCTOU) Race Condition in exec Script Preflight Validator

CVE ID :CVE-2026-43529 Published : 5. Mai 2026 11:25 | 56 Minuten ago Description :OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed function that allows local attackers to bypass workspace boundary checks. An attacker with workspace write access can race-condition swap the target file between validation and preflight read, causing the validator to inspect a different file identity than the one that passed the initial boundary check. Severity: 2.5 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-43528 - OpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig Aliases

CVE ID :CVE-2026-43528 Published : 5. Mai 2026 11:24 | 56 Minuten ago Description :OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with config read access can exploit this to obtain provider API keys, gateway authentication material, and channel credentials that should have been redacted. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-6262 - Betheme <= 28.4 - Authenticated (Contributor+) Arbitrary File Deletion via 'mfn-icon-upload'

CVE ID :CVE-2026-6262 Published : May 5, 2026, 12:16 p.m. | 2 hours, 5 minutes ago Description :The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function workflow using a user-controlled upload path (`mfn-icon-upload`) in a filesystem move operation without constraining it to the uploads directory. This makes it possible for authenticated attackers, with contributor-level access and above, to move/delete arbitrary local files via path traversal. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
News
WhatsApp Vulnerability Lets Attackers Leverage Instagram Reels to Execute Malicious URLs

WhatsApp Vulnerability Lets Attackers Leverage Instagram Reels to Execute Malicious URLs Meta has disclosed a medium-severity security vulnerability in WhatsApp that could allow threat actors to exploit Instagram Reels integration to trigger arbitrary URL processing on victim devices, pot ... Read more Published Date: May 05, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-23866 CVE-2026-23863

CVEfeed Newsroom05 mag 2026
News
Kritiek lek in Androidtelefoons maakt remote code execution mogelijk

Kritiek lek in Androidtelefoons maakt remote code execution mogelijk Een kritieke kwetsbaarheid in Androidtelefoons maakt remote code execution (RCE) mogelijk, zonder dat er enige interactie van gebruikers is vereist. Google heeft updates uitgebracht om het probleem te ... Read more Published Date: May 05, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-0073

CVEfeed Newsroom05 mag 2026
VulnerabilitàAlta
CVE-2026-43870 - Apache Thrift: Node.js web_server.js multi-vulnerability

CVE ID :CVE-2026-43870 Published : May 5, 2026, 9:16 a.m. | 1 hour, 5 minutes ago Description :Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-43868 - Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern

CVE ID :CVE-2026-43868 Published : May 5, 2026, 9:16 a.m. | 1 hour, 5 minutes ago Description :Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-3359 (CVSS 7.5)

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1.15.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)05 mag 2026
VulnerabilitàAlta
CVE-2026-3359 - Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs'

CVE ID :CVE-2026-3359 Published : May 5, 2026, 9:16 a.m. | 1 hour, 5 minutes ago Description :The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1.15.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-3601 - User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Limited Page Content Modification

CVE ID :CVE-2026-3601 Published : May 5, 2026, 9:16 a.m. | 1 hour, 5 minutes ago Description :The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to append shortcode content to arbitrary pages they do not own or have permission to edit. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026

Pagina 1843 di 3069

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.