Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37493 risultati

VulnerabilitàAlta
CVE-2026-7549 - SourceCodester Pharmacy Sales and Inventory System ajax.php delete_customer sql injection

CVE ID :CVE-2026-7549 Published : May 1, 2026, 5:16 a.m. | 7 hours, 2 minutes ago Description :A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete_customer. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-42994 - Bitwarden CLI Malicious Code Injection

CVE ID :CVE-2026-42994 Published : May 1, 2026, 5:16 a.m. | 7 hours, 3 minutes ago Description :Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
News
Critical Wireshark Vulnerabilities Let Attackers Execute Arbitrary Code Via Malformed Packets

Critical Wireshark Vulnerabilities Let Attackers Execute Arbitrary Code Via Malformed Packets Wireshark, the world’s most widely used open-source network protocol analyzer, has released a major security update addressing over 40 vulnerabilities, several of which enable arbitrary code execution ... Read more Published Date: May 01, 2026 (3 days, 3 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom01 mag 2026
VulnerabilitàAlta
CVE-2026-7554 - D-Link M60 httpd password recovery

CVE ID :CVE-2026-7554 Published : May 1, 2026, 6:16 a.m. | 6 hours, 2 minutes ago Description :A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the file /usr/bin/httpd. This manipulation causes weak password recovery. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. Severity: 5.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-7548 (CVSS 8.8)

A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

NVD (NIST)01 mag 2026
VulnerabilitàCritica
CVE-2026-7546 (CVSS 9.8)

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

NVD (NIST)01 mag 2026
VulnerabilitàAlta
CVE-2026-7548 - Totolink NR1800X cstecgi.cgi sub_41A68C command injection

CVE ID :CVE-2026-7548 Published : May 1, 2026, 3:16 a.m. | 9 hours, 3 minutes ago Description :A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-7546 - Totolink NR1800X lighttpd find_host_ip stack-based overflow

CVE ID :CVE-2026-7546 Published : May 1, 2026, 3:16 a.m. | 7 hours, 2 minutes ago Description :A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-7545 (CVSS 7.3)

A weakness has been identified in SourceCodester Advanced School Management System 1.0. The affected element is an unknown function of the file commonController.php of the component checkEmail Endpoint. This manipulation causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

NVD (NIST)01 mag 2026
VulnerabilitàCritica
CVE-2026-7538 (CVSS 9.8)

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument proto leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

NVD (NIST)01 mag 2026
VulnerabilitàAlta
CVE-2026-7545 - SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection

CVE ID :CVE-2026-7545 Published : May 1, 2026, 2:16 a.m. | 8 hours, 2 minutes ago Description :A weakness has been identified in SourceCodester Advanced School Management System 1.0. The affected element is an unknown function of the file commonController.php of the component checkEmail Endpoint. This manipulation causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026
VulnerabilitàAlta
CVE-2026-7538 - Totolink A8000RU CGI cstecgi.cgi vulnerability os command injection

CVE ID :CVE-2026-7538 Published : May 1, 2026, 2:16 a.m. | 8 hours, 2 minutes ago Description :A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument proto leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 mag 2026

Pagina 1947 di 3125

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.