Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

11862 risultati

VulnerabilitàAlta
CVE-2019-25681 - Xlight FTP Server 3.9.1 SEH Overwrite Buffer Overflow

CVE ID :CVE-2019-25681 Published : April 5, 2026, 9:16 p.m. | 2 hours, 38 minutes ago Description :Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual server configuration to trigger a buffer overflow that corrupts the SEH chain and enables potential code execution. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2019-25684 - OpenDocMan 1.3.4 SQL Injection via where Parameter

CVE ID :CVE-2019-25684 Published : April 5, 2026, 9:16 p.m. | 2 hours, 38 minutes ago Description :OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2019-25682 - CMSsite 1.0 Cross-Site Request Forgery via users.php

CVE ID :CVE-2019-25682 Published : April 5, 2026, 9:16 p.m. | 2 hours, 38 minutes ago Description :CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like source=add_user, source=edit_user, or del=1 to create, modify, or delete admin accounts. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2019-25683 - FileZilla 3.40.0 Denial of Service via Local Search

CVE ID :CVE-2019-25683 Published : April 5, 2026, 9:16 p.m. | 2 hours, 38 minutes ago Description :FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2019-25678 (CVSS 8.2)

C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the site parameter. Attackers can send GET requests to the users_select.php endpoint with crafted SQL payloads to extract sensitive database information including patient records and system credentials.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2019-25676 (CVSS 8.2)

Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view parameter in list-details.php to execute arbitrary code or extract database information.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2019-25675 (CVSS 8.2)

eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with union-based SQL injection to authenticate as administrator, then leverage authenticated file disclosure vulnerabilities in language_file.php to read arbitrary PHP files from the server.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2019-25674 (CVSS 8.2)

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php with malicious 'post' values to extract sensitive database information or perform time-based blind SQL injection attacks.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2019-25673 (CVSS 8.8)

UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2019-25677 - WinRAR 5.61 Denial of Service via Malformed Language File

CVE ID :CVE-2019-25677 Published : April 5, 2026, 9:16 p.m. | 38 minutes ago Description :WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing an access violation at memory address 004F1DB8 when the application attempts to read invalid data. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2019-25672 (CVSS 8.2)

PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter. Attackers can submit POST requests to the comment submission endpoint with RLIKE-based boolean SQL injection payloads to extract sensitive database information.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2019-25671 (CVSS 8.8)

VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter. Attackers can send POST requests to the changeip.php endpoint with malicious payload in the mtu_eth0 field to execute commands as the apache user.

NVD (NIST)05 apr 2026

Pagina 189 di 989

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.