Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37121 risultati

VulnerabilitàAlta
CVE-2026-7653 - r-huijts mcp-server-rijksmuseum MCP index.ts open_image_in_browser os command injection

CVE ID :CVE-2026-7653 Published : May 2, 2026, 4:16 p.m. | 16 hours, 3 minutes ago Description :A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument imageUrl results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7644 (CVSS 7.3)

A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)02 mag 2026
VulnerabilitàAlta
CVE-2026-7643 - ChatGPTNextWeb NextChat API Endpoint Next.js cross-domain policy

CVE ID :CVE-2026-7643 Published : May 2, 2026, 3:16 p.m. | 15 hours, 3 minutes ago Description :A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7642 - pskill9 website-downloader MCP index.ts download_website os command injection

CVE ID :CVE-2026-7642 Published : May 2, 2026, 3:16 p.m. | 15 hours, 3 minutes ago Description :A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument outputPath results in os command injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7644 - ChatGPTNextWeb NextChat actions.ts addMcpServer improper authorization

CVE ID :CVE-2026-7644 Published : May 2, 2026, 3:16 p.m. | 15 hours, 3 minutes ago Description :A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7633 - Totolink N300RH cstecgi.cgi setUploadSetting file inclusion

CVE ID :CVE-2026-7633 Published : May 2, 2026, 3:16 p.m. | 15 hours, 3 minutes ago Description :A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7645 - ruvnet sublinear-time-solver MCP server.js export_state path traversal

CVE ID :CVE-2026-7645 Published : May 2, 2026, 4:16 p.m. | 16 hours, 3 minutes ago Description :A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP Interface. The manipulation results in path traversal. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7632 (CVSS 7.3)

A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

NVD (NIST)02 mag 2026
VulnerabilitàAlta
CVE-2026-7630 (CVSS 7.3)

A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of the component Installation Endpoint. The manipulation leads to improper authentication. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 45758e4ec22451ab944ae2ae826b1e70f6450dc9. It is recommended to apply a patch to fix this issue.

NVD (NIST)02 mag 2026
VulnerabilitàAlta
CVE-2026-7630 - innocommerce InnoShop Installation Endpoint InstallServiceProvider.php boot improper authentication

CVE ID :CVE-2026-7630 Published : May 2, 2026, 2:16 p.m. | 14 hours, 3 minutes ago Description :A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of the component Installation Endpoint. The manipulation leads to improper authentication. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 45758e4ec22451ab944ae2ae826b1e70f6450dc9. It is recommended to apply a patch to fix this issue. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-7632 - code-projects Online Hospital Management System viewappointment.php sql injection

CVE ID :CVE-2026-7632 Published : May 2, 2026, 2:16 p.m. | 16 hours, 3 minutes ago Description :A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 mag 2026
VulnerabilitàAlta
CVE-2026-2554 (CVSS 8.1)

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the 'wcfm_delete_wcfm_customer' due to missing validation on the 'customerid' user controlled key. This makes it possible for authenticated attackers, with Vendor-level access and above, to delete arbitrary users, including Administrators.

NVD (NIST)02 mag 2026

Pagina 1896 di 3094

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.