Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38037 risultati

VulnerabilitàAlta
CVE-2026-38936 - Apache Diskover Cross-Site Scripting Vulnerability

CVE ID :CVE-2026-38936 Published : April 27, 2026, 5:16 p.m. | 58 minutes ago Description :A reflected cross-site scripting (XSS) vulnerability exists in diskover-community Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-38934 - Diskoverdata Diskover-Community Cross Site Request Forgery Privilege Escalation

CVE ID :CVE-2026-38934 Published : April 27, 2026, 5:16 p.m. | 58 minutes ago Description :Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-30346 - Hunvreus DevPush Open Redirect Vulnerability

CVE ID :CVE-2026-30346 Published : April 27, 2026, 5:16 p.m. | 58 minutes ago Description :An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-30462 - Daylight Studio FuelCMS Path Traversal Vulnerability

CVE ID :CVE-2026-30462 Published : April 27, 2026, 5:16 p.m. | 58 minutes ago Description :A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a directory traversal. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7143 - 1000 Projects Portfolio Management System MCA block_status.php sql injection

CVE ID :CVE-2026-7143 Published : April 27, 2026, 6:16 p.m. | 1 hour, 58 minutes ago Description :A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation of the argument q leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàCritica
CVE-2026-7138 (CVSS 9.8)

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument tz results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.

NVD (NIST)27 apr 2026
VulnerabilitàCritica
CVE-2026-7137 (CVSS 9.8)

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument sambaEnabled leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

NVD (NIST)27 apr 2026
VulnerabilitàAlta
CVE-2026-7138 - Totolink A8000RU CGI cstecgi.cgi setNtpCfg os command injection

CVE ID :CVE-2026-7138 Published : April 27, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument tz results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7137 - Totolink A8000RU CGI cstecgi.cgi setStorageCfg os command injection

CVE ID :CVE-2026-7137 Published : April 27, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument sambaEnabled leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàCritica
CVE-2026-7136 (CVSS 9.8)

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wanIdx can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

NVD (NIST)27 apr 2026
VulnerabilitàAlta
CVE-2026-7136 - Totolink A8000RU CGI cstecgi.cgi setDmzCfg os command injection

CVE ID :CVE-2026-7136 Published : April 27, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wanIdx can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-41463 (CVSS 8.8)

ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions to write files outside the intended extraction directory by crafting ZIP archives with directory traversal sequences. Attackers can exploit unvalidated archive extraction to write a PHP webshell to a web-accessible directory and achieve remote code execution with the privileges of the web server process.

NVD (NIST)27 apr 2026

Pagina 2052 di 3170

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.