Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36830 risultati

VulnerabilitàAlta
CVE-2026-5100 - AWP Classifieds <= 4.4.5 - Unauthenticated SQL Injection via 'regions'

CVE ID :CVE-2026-5100 Published : May 5, 2026, 3:15 a.m. | 3 hours, 5 minutes ago Description :The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-4409 - Subscribe To Comments Reloaded <= 240119 - Improper Authorization to Unauthenticated Arbitrary Subscription Management

CVE ID :CVE-2026-4409 Published : May 5, 2026, 3:15 a.m. | 3 hours, 5 minutes ago Description :The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This makes it possible for unauthenticated attackers to extract the global key from any public post page, forge authorization keys and manage comment subscription preferences for arbitrary users Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-2868 - Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'separatorIconSVG'

CVE ID :CVE-2026-2868 Published : May 5, 2026, 3:15 a.m. | 1 hour, 4 minutes ago Description :The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'separatorIconSVG' parameter in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàCritica
CVE-2025-13618 (CVSS 9.8)

The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can register with in the mentoring_process_registration() function. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.

NVD (NIST)05 mag 2026
VulnerabilitàAlta
CVE-2025-13618 - Mentoring <= 1.2.8 - Unauthenticated Privilege Escalation in mentoring_process_registration

CVE ID :CVE-2025-13618 Published : May 5, 2026, 3:15 a.m. | 1 hour, 5 minutes ago Description :The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can register with in the mentoring_process_registration() function. This makes it possible for unauthenticated attackers to register with administrator-level user accounts. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
News
Critical 9.8 CVSS Flaws in Qualcomm Chipsets Enable Remote Takeover

Critical 9.8 CVSS Flaws in Qualcomm Chipsets Enable Remote Takeover Qualcomm has released its May 2026 Security Bulletin, disclosing a series of high-impact vulnerabilities across its proprietary software and hardware components. The bulletin highlights several Critic ... Read more Published Date: May 05, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
News
Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks

Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Exe ... Read more Published Date: May 05, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
News
Gremlin Injection Flaw in Apache Atlas Exposes Enterprise Data

Gremlin Injection Flaw in Apache Atlas Exposes Enterprise Data Apache Atlas, the foundational governance service that many enterprises rely on to manage compliance and data catalogs within the Hadoop ecosystem, has been hit by a high-stakes security flaw. The vul ... Read more Published Date: May 05, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
VulnerabilitàCritica
CVE-2026-5722 (CVSS 9.8)

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a valid guest verification token for an attacker-controlled email, changing the same guest customer email to the target account email through the public waitlist flow, and then using the original verification link.

NVD (NIST)05 mag 2026
VulnerabilitàAlta
CVE-2026-5722 - MoreConvert Pro <= 1.9.14 - Authentication Bypass via Waitlist Guest Verification Token Reuse

CVE ID :CVE-2026-5722 Published : May 5, 2026, 2:16 a.m. | 2 hours, 4 minutes ago Description :The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a valid guest verification token for an attacker-controlled email, changing the same guest customer email to the target account email through the public waitlist flow, and then using the original verification link. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
News
Millions at Risk: Apache HTTP Server Fixes Critical Remote Code Execution Flaw

Millions at Risk: Apache HTTP Server Fixes Critical Remote Code Execution Flaw The Apache HTTP Server Project, the long-standing standard for secure and extensible web services on UNIX and Windows, has released a series of security updates to address a wide range of vulnerabilit ... Read more Published Date: May 05, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
News
Multi Apache Polaris Flaws Granting Unauthorized Multi-Cloud Access

Multi Apache Polaris Flaws Granting Unauthorized Multi-Cloud Access The Apache Polaris project, a popular open-source catalog for Apache Iceberg, has released a major security update to address four critical vulnerabilities that could allow attackers to bypass storage ... Read more Published Date: May 05, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026

Pagina 1848 di 3070

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.