Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

37777 risultati

VulnerabilitàAlta
CVE-2026-7396 - NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal

CVE ID :CVE-2026-7396 Published : April 29, 2026, 5:30 p.m. | 47 minutes ago Description :A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-5712 - IdentityIQ Role Editor Incorrect Authorization Vulnerability

CVE ID :CVE-2026-5712 Published : April 29, 2026, 5:18 p.m. | 59 minutes ago Description :This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7393 - SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload

CVE ID :CVE-2026-7393 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-6915 - Flaw in the updateUser Command May Allow Unauthorized Configuration Change

CVE ID :CVE-2026-6915 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7392 - SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection

CVE ID :CVE-2026-7392 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7391 - SourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection

CVE ID :CVE-2026-7391 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action=save_supplier. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-6914 - MD5 checksum creation may cause availability loss

CVE ID :CVE-2026-6914 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server. This issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB Server v8.0 versions prior to 8.0.21, MongoDB Server v7.0 versions prior to 7.0.32 Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-0206 - SonicOS Stack-based Buffer Overflow Vulnerability

CVE ID :CVE-2026-0206 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-0205 - SonicOS Path Traversal Vulnerability

CVE ID :CVE-2026-0205 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-0204 - SonicOS Unauthenticated Access Control Bypass

CVE ID :CVE-2026-0204 Published : April 29, 2026, 5:16 p.m. | 1 hour, 1 minute ago Description :A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7394 - SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection

CVE ID :CVE-2026-7394 Published : April 29, 2026, 5:15 p.m. | 1 hour, 2 minutes ago Description :A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 apr 2026
VulnerabilitàAlta
CVE-2026-7389 (CVSS 7.3)

A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.php. The manipulation of the argument sort_asc leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)29 apr 2026

Pagina 1994 di 3149

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.