Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36834 risultati

VulnerabilitàCritica
CVE-2026-5722 (CVSS 9.8)

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a valid guest verification token for an attacker-controlled email, changing the same guest customer email to the target account email through the public waitlist flow, and then using the original verification link.

NVD (NIST)05 mag 2026
VulnerabilitàAlta
CVE-2026-5722 - MoreConvert Pro <= 1.9.14 - Authentication Bypass via Waitlist Guest Verification Token Reuse

CVE ID :CVE-2026-5722 Published : May 5, 2026, 2:16 a.m. | 2 hours, 4 minutes ago Description :The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a valid guest verification token for an attacker-controlled email, changing the same guest customer email to the target account email through the public waitlist flow, and then using the original verification link. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
News
Millions at Risk: Apache HTTP Server Fixes Critical Remote Code Execution Flaw

Millions at Risk: Apache HTTP Server Fixes Critical Remote Code Execution Flaw The Apache HTTP Server Project, the long-standing standard for secure and extensible web services on UNIX and Windows, has released a series of security updates to address a wide range of vulnerabilit ... Read more Published Date: May 05, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
News
Multi Apache Polaris Flaws Granting Unauthorized Multi-Cloud Access

Multi Apache Polaris Flaws Granting Unauthorized Multi-Cloud Access The Apache Polaris project, a popular open-source catalog for Apache Iceberg, has released a major security update to address four critical vulnerabilities that could allow attackers to bypass storage ... Read more Published Date: May 05, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
News
Critical Zero-Click Android Flaw Grants Remote Shell Access Without Interaction

Critical Zero-Click Android Flaw Grants Remote Shell Access Without Interaction Google has issued an urgent warning in its May 2026 Android Security Bulletin regarding a critical vulnerability discovered in the core System component. The flaw, tracked as CVE-2026-0073, could allo ... Read more Published Date: May 05, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
News
Apache Neethi Patches Triple Threat of DoS and Redirection Flaws

Apache Neethi Patches Triple Threat of DoS and Redirection Flaws The Apache Neethi project, a cornerstone framework used by Java developers to implement WS-Policy specifications, has released version 3.2.2 to address three significant security vulnerabilities. Thes ... Read more Published Date: May 05, 2026 (23 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
VulnerabilitàAlta
CVE-2026-44029 - Nix Directory Traversal Vulnerability

CVE ID :CVE-2026-44029 Published : May 5, 2026, 1:16 a.m. | 3 hours, 4 minutes ago Description :An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7); Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-44028 - Nix Lix Unbounded Recursion Stack-to-Heap Overflow

CVE ID :CVE-2026-44028 Published : May 5, 2026, 1:16 a.m. | 1 hour, 4 minutes ago Description :An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite memory on the heap and could allow arbitrary code execution as the Nix daemon (run as root in multi-user installations) if ASLR hardening is bypassed. This can be exploited by all users able to connect to the daemon (e.g., in Nix, this is configurable via the allowed-users setting, defaulting to all users). The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 for Nix (introduced in 2.24.4); and 2.95.2, 2.94.2, and 2.93.4 for Lix (introduced in 2.93.0). Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
News
Maximum Severity Flaw: How a Newline Character Shattered Gotenberg’s PDF Security

Maximum Severity Flaw: How a Newline Character Shattered Gotenberg’s PDF Security Thousands of companies rely on Gotenberg, the Docker-based API for document-to-PDF conversion, to handle production workloads. However, recent security disclosures have unveiled a series of critical f ... Read more Published Date: May 05, 2026 (23 hours, 25 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom05 mag 2026
VulnerabilitàAlta
CVE-2026-7788 (CVSS 7.3)

A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the function update_document/continue_document/delete_document/get_content of the file app/routes/document.py. Performing a manipulation of the argument DOCS_DIR/path results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)05 mag 2026
VulnerabilitàAlta
CVE-2026-7788 - Axle-Bucamp MCP-Docusaurus document.py get_content path traversal

CVE ID :CVE-2026-7788 Published : May 5, 2026, 12:16 a.m. | 2 hours, 4 minutes ago Description :A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the function update_document/continue_document/delete_document/get_content of the file app/routes/document.py. Performing a manipulation of the argument DOCS_DIR/path results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 mag 2026
VulnerabilitàAlta
CVE-2026-7785 (CVSS 7.3)

A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the function quick_capture of the file pyshark_mcp.py. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)05 mag 2026

Pagina 1849 di 3070

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.