Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45447 risultati

VulnerabilitàAlta
CVE-2026-95586 - WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.50 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-95586 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-95530 - WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-95530 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-95529 - WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-95529 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-95528 - WordPress Core Web Vitals & PageSpeed Booster plugin <= 1.0.31 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-95528 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-95527 - WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vulnerability

CVE ID :CVE-2026-95527 Published : Sept. 23, 2026, 6:14 p.m. | 30 minutes ago Description :Unauthenticated Broken Access Control in Conekta Payment Gateway Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàCritica
CVE-2026-96759 (CVSS 9.8)

orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI specification that executes when generated hooks are called.

NVD (NIST)23 set 2026
VulnerabilitàCritica
CVE-2026-96758 (CVSS 9.8)

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client builds FormData bodies with consumer process privileges.

NVD (NIST)23 set 2026
VulnerabilitàCritica
CVE-2026-96757 (CVSS 9.8)

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that executes when generated fetch operations or mock resolvers are invoked.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-96756 (CVSS 8.1)

orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled.

NVD (NIST)23 set 2026
VulnerabilitàCritica
CVE-2026-96755 (CVSS 9.8)

orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.

NVD (NIST)23 set 2026
VulnerabilitàCritica
CVE-2026-96754 (CVSS 9.8)

orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-96514 (CVSS 7.3)

A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)23 set 2026

Pagina 207 di 3788

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.