News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
36834 risultati
The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a valid guest verification token for an attacker-controlled email, changing the same guest customer email to the target account email through the public waitlist flow, and then using the original verification link.
CVE ID :CVE-2026-5722 Published : May 5, 2026, 2:16 a.m. | 2 hours, 4 minutes ago Description :The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a valid guest verification token for an attacker-controlled email, changing the same guest customer email to the target account email through the public waitlist flow, and then using the original verification link. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Millions at Risk: Apache HTTP Server Fixes Critical Remote Code Execution Flaw The Apache HTTP Server Project, the long-standing standard for secure and extensible web services on UNIX and Windows, has released a series of security updates to address a wide range of vulnerabilit ... Read more Published Date: May 05, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.
Multi Apache Polaris Flaws Granting Unauthorized Multi-Cloud Access The Apache Polaris project, a popular open-source catalog for Apache Iceberg, has released a major security update to address four critical vulnerabilities that could allow attackers to bypass storage ... Read more Published Date: May 05, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.
Critical Zero-Click Android Flaw Grants Remote Shell Access Without Interaction Google has issued an urgent warning in its May 2026 Android Security Bulletin regarding a critical vulnerability discovered in the core System component. The flaw, tracked as CVE-2026-0073, could allo ... Read more Published Date: May 05, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.
Apache Neethi Patches Triple Threat of DoS and Redirection Flaws The Apache Neethi project, a cornerstone framework used by Java developers to implement WS-Policy specifications, has released version 3.2.2 to address three significant security vulnerabilities. Thes ... Read more Published Date: May 05, 2026 (23 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-44029 Published : May 5, 2026, 1:16 a.m. | 3 hours, 4 minutes ago Description :An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7); Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-44028 Published : May 5, 2026, 1:16 a.m. | 1 hour, 4 minutes ago Description :An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite memory on the heap and could allow arbitrary code execution as the Nix daemon (run as root in multi-user installations) if ASLR hardening is bypassed. This can be exploited by all users able to connect to the daemon (e.g., in Nix, this is configurable via the allowed-users setting, defaulting to all users). The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 for Nix (introduced in 2.24.4); and 2.95.2, 2.94.2, and 2.93.4 for Lix (introduced in 2.93.0). Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Maximum Severity Flaw: How a Newline Character Shattered Gotenberg’s PDF Security Thousands of companies rely on Gotenberg, the Docker-based API for document-to-PDF conversion, to handle production workloads. However, recent security disclosures have unveiled a series of critical f ... Read more Published Date: May 05, 2026 (23 hours, 25 minutes ago) Vulnerabilities has been mentioned in this article.
A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the function update_document/continue_document/delete_document/get_content of the file app/routes/document.py. Performing a manipulation of the argument DOCS_DIR/path results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
CVE ID :CVE-2026-7788 Published : May 5, 2026, 12:16 a.m. | 2 hours, 4 minutes ago Description :A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the function update_document/continue_document/delete_document/get_content of the file app/routes/document.py. Performing a manipulation of the argument DOCS_DIR/path results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the function quick_capture of the file pyshark_mcp.py. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Pagina 1849 di 3070