News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
45446 risultati
CVE ID :CVE-2026-86867 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pages/chat/control.py` that load a Conversation record by its ID without comparing the requester's `user_id` to the conversation's owner `Conversation.user`. This allows any authenticated user to perform the following actions: 1. Read other user's chat transcripts, RAG retrieval history, AI-generated plots, and chat suggestions. 2. Permanently delete another user's conversation. 3. Rename another user's conversation. 4. Overwrite another user's conversation's chat suggestion list. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-86930 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18944 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-18944. Reason: This candidate is a reservation duplicate of CVE-2026-18944. Notes: All CVE users should reference CVE-2026-18944 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-95604 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Unauthenticated Broken Access Control in Loops & Logic Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-95602 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Unauthenticated Insecure Direct Object References (IDOR) in YITH WooCommerce Request A Quote Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-95603 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Shop manager PHP Object Injection in Reycob Product Import Export Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-95601 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Unauthenticated SQL Injection in Product Filter by WBW Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-95600 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Unauthenticated Sensitive Data Exposure in TrustedLogin Connector Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-95592 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Unauthenticated Insecure Direct Object References (IDOR) in Team Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-95593 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Editor SQL Injection in Ultimeter Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-95590 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Subscriber SQL Injection in Tainacan Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-95586 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 206 di 3788