Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38053 risultati

VulnerabilitàAlta
CVE-2026-7137 - Totolink A8000RU CGI cstecgi.cgi setStorageCfg os command injection

CVE ID :CVE-2026-7137 Published : April 27, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument sambaEnabled leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàCritica
CVE-2026-7136 (CVSS 9.8)

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wanIdx can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

NVD (NIST)27 apr 2026
VulnerabilitàAlta
CVE-2026-7136 - Totolink A8000RU CGI cstecgi.cgi setDmzCfg os command injection

CVE ID :CVE-2026-7136 Published : April 27, 2026, 4:16 p.m. | 1 hour, 58 minutes ago Description :A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wanIdx can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-41463 (CVSS 8.8)

ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions to write files outside the intended extraction directory by crafting ZIP archives with directory traversal sequences. Attackers can exploit unvalidated archive extraction to write a PHP webshell to a web-accessible directory and achieve remote code execution with the privileges of the web server process.

NVD (NIST)27 apr 2026
VulnerabilitàCritica
CVE-2026-41462 (CVSS 9.8)

ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username field at the authentication endpoint to create privileged accounts, read sensitive data, and execute operating system commands if the database user has elevated permissions.

NVD (NIST)27 apr 2026
News
Notepad++ Vulnerability Allows Attackers to Crash Application, Leak Memory Data

Notepad++ Vulnerability Allows Attackers to Crash Application, Leak Memory Data A security vulnerability has been identified in Notepad++, one of the most widely used open-source text editors among developers and IT professionals. The vulnerability CVE-2026-3008, which could allo ... Read more Published Date: Apr 27, 2026 (1 day, 14 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom27 apr 2026
VulnerabilitàAlta
CVE-2026-6970 - authd Denial of Service and Local Privilege Escalation

CVE ID :CVE-2026-6970 Published : April 27, 2026, 3:28 p.m. | 46 minutes ago Description :authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a user's primary group ID (GID) differs from their UID, either because the account was created with authd prior to version 0.5.4 or because the primary group was manually changed via the `authctl group set-gid` command, and the user's identity provider record is updated, authd incorrectly resets the user's primary group ID to their UID upon next login. This causes newly created files and directories to be owned by the wrong group, causing denial of service issues, and potentially granting unintended access to other local users and allowing local privilege escalation. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7131 (CVSS 7.3)

A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /loginuser.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

NVD (NIST)27 apr 2026
VulnerabilitàAlta
CVE-2026-7132 - code-projects Online Lot Reservation System download.php readfile path traversal

CVE ID :CVE-2026-7132 Published : April 27, 2026, 3:16 p.m. | 59 minutes ago Description :A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7133 - code-projects Online Lot Reservation System activity.php unrestricted upload

CVE ID :CVE-2026-7133 Published : April 27, 2026, 3:16 p.m. | 59 minutes ago Description :A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument directory causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-7131 - code-projects Online Lot Reservation System loginuser.php sql injection

CVE ID :CVE-2026-7131 Published : April 27, 2026, 3:16 p.m. | 59 minutes ago Description :A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unknown function of the file /loginuser.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026
VulnerabilitàAlta
CVE-2026-40514 - SmarterTools SmarterMail < Build 9610 Cryptographic Weakness via Weak RNG

CVE ID :CVE-2026-40514 Published : April 27, 2026, 3:16 p.m. | 59 minutes ago Description :SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vectors derived from System.Random seeded with insufficient entropy, reducing the seed space to approximately 19,000 possible values. An unauthenticated attacker can use the attachment download endpoint as an oracle to determine the seed in use and derive encryption keys and initialization vectors to forge sharing tokens for arbitrary emails, attachments, or file storage contents without prior access to the targeted content. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 apr 2026

Pagina 2054 di 3172

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.