Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36985 risultati

VulnerabilitàAlta
CVE-2026-7684 (CVSS 8.8)

A security vulnerability has been detected in Edimax BR-6428nC up to 1.16. This impacts an unknown function of the file /goform/setWAN. Such manipulation of the argument pptpDfGateway  leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)03 mag 2026
VulnerabilitàAlta
CVE-2026-7684 - Edimax BR-6428nC setWAN buffer overflow

CVE ID :CVE-2026-7684 Published : May 3, 2026, 7:16 a.m. | 15 hours, 3 minutes ago Description :A security vulnerability has been detected in Edimax BR-6428nC up to 1.16. This impacts an unknown function of the file /goform/setWAN. Such manipulation of the argument pptpDfGateway leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7685 - Edimax BR-6208AC setWAN buffer overflow

CVE ID :CVE-2026-7685 Published : May 3, 2026, 7:16 a.m. | 15 hours, 3 minutes ago Description :A vulnerability was detected in Edimax BR-6208AC up to 1.02. Affected is an unknown function of the file /goform/setWAN. Performing a manipulation of the argument pptpDfGateway results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7683 - Edimax BR-6428nC Web setWAN command injection

CVE ID :CVE-2026-7683 Published : May 3, 2026, 7:16 a.m. | 15 hours, 3 minutes ago Description :A weakness has been identified in Edimax BR-6428nC up to 1.16. This affects an unknown function of the file /goform/setWAN of the component Web Interface. This manipulation of the argument pppUserName/pptpUserName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-5337 - Frontend File Manager Plugin <= 23.6 - Subscriber+ Arbitrary Download Access via IDOR

CVE ID :CVE-2026-5337 Published : May 3, 2026, 7:16 a.m. | 15 hours, 3 minutes ago Description :During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user authorization for the requested uploaded file when processing download requests. By modifying the value of the 'file_id' parameter in the download endpoint (e.g., http://localhost/?do=wpfm_download&file_id=40&nm_file_nonce=a36fb893f1), an attacker can access files belonging to other users, including privileged users such as administrators. This allows unauthorized access/read to sensitive data stored within the application. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7682 - Edimax BR-6208AC L2TP Mode setWAN command injection

CVE ID :CVE-2026-7682 Published : May 3, 2026, 7:16 a.m. | 15 hours, 3 minutes ago Description :A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
News
TheCyberThrone CyberSecurity Newsletter Top 5 Articles – April 2026

TheCyberThrone CyberSecurity Newsletter Top 5 Articles – April 2026 May 3, 2026Welcome to TheCyberThrone cybersecurity month in review will be posted covering the important security happenings. This review is for the month ending April 2026.Subscribers favorite #1CVE- ... Read more Published Date: May 03, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34621

CVEfeed Newsroom03 mag 2026
News
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed security flaw impacting various Linux distributions to its Known Exploited Vulnerabilities (KEV) c ... Read more Published Date: May 03, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-31431 CVE-2026-33626 CVE-2026-32202 CVE-2026-3854

CVEfeed Newsroom03 mag 2026
VulnerabilitàAlta
CVE-2026-5063 (CVSS 7.2)

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in the submit_nex_form() function in versions up to, and including, 9.1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD (NIST)03 mag 2026
VulnerabilitàAlta
CVE-2026-7679 (CVSS 7.3)

A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/service/impl/OAuth2TokenServiceImpl.java. Performing a manipulation results in improper authentication. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)03 mag 2026
VulnerabilitàAlta
CVE-2026-7678 - YunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injection

CVE ID :CVE-2026-7678 Published : May 3, 2026, 5:15 a.m. | 9 hours, 4 minutes ago Description :A vulnerability was identified in YunaiV yudao-cloud up to 2026.01. This affects the function getDataBySQL of the file yudao-module-report-biz/src/main/java/io/github/ruoyi/report/service/impl/GoViewDataServiceImpl.java. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026
VulnerabilitàAlta
CVE-2026-7679 - YunaiV yudao-cloud OAuth2TokenServiceImpl.java getAccessToken improper authentication

CVE ID :CVE-2026-7679 Published : May 3, 2026, 5:15 a.m. | 11 hours, 4 minutes ago Description :A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/service/impl/OAuth2TokenServiceImpl.java. Performing a manipulation results in improper authentication. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 mag 2026

Pagina 1882 di 3083

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.