Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38074 risultati

VulnerabilitàAlta
CVE-2026-7043 - GreenCMS index.php pluginAddLocal unrestricted upload

CVE ID :CVE-2026-7043 Published : April 26, 2026, 10:17 p.m. | 1 hour, 57 minutes ago Description :A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2018-25294 (CVSS 7.5)

CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition.

NVD (NIST)26 apr 2026
VulnerabilitàAlta
CVE-2018-25283 (CVSS 8.4)

iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save Path for Snapshot and Record file' field that allows local attackers to execute arbitrary code. Attackers can input a crafted payload exceeding 260 bytes through the System Setup interface to overwrite SEH records and execute shellcode with application privileges.

NVD (NIST)26 apr 2026
VulnerabilitàAlta
CVE-2018-25263 (CVSS 8.4)

Faleemi Desktop Software 1.8.2 contains a local buffer overflow vulnerability in the Device alias field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Device alias field within the Managing Log interface to execute arbitrary code with calculator proof-of-concept execution.

NVD (NIST)26 apr 2026
VulnerabilitàAlta
CVE-2026-7059 - 666ghj MiroFish Query Parameter simulation.py get_simulation_posts path traversal

CVE ID :CVE-2026-7059 Published : April 26, 2026, 10:17 p.m. | 3 hours, 57 minutes ago Description :A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. Performing a manipulation of the argument Platform results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-6785 - Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150

CVE ID :CVE-2026-6785 Published : April 26, 2026, 7:53 p.m. | 2 hours, 21 minutes ago Description :Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-6786 - Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150

CVE ID :CVE-2026-6786 Published : April 26, 2026, 7:53 p.m. | 2 hours, 21 minutes ago Description :Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-7058 - 666ghj MiroFish Inter-Process Communication simulation_ipc.py SimulationIPCClient.send_command command injection

CVE ID :CVE-2026-7058 Published : April 26, 2026, 10:17 p.m. | 3 hours, 57 minutes ago Description :A vulnerability has been found in 666ghj MiroFish up to 0.1.2. The impacted element is the function SimulationIPCClient.send_command of the file backend/app/services/simulation_ipc.py of the component Inter-Process Communication. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-7057 - Tenda F456 httpd setcfm buffer overflow

CVE ID :CVE-2026-7057 Published : April 26, 2026, 10:17 p.m. | 3 hours, 57 minutes ago Description :A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of the argument funcname/funcpara1 causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-7056 - Tenda F456 httpd SafeUrlFilter fromSafeUrlFilter buffer overflow

CVE ID :CVE-2026-7056 Published : April 26, 2026, 10:17 p.m. | 3 hours, 57 minutes ago Description :A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-7055 - Tenda F456 httpd VirtualSer fromVirtualSer buffer overflow

CVE ID :CVE-2026-7055 Published : April 26, 2026, 10:17 p.m. | 3 hours, 57 minutes ago Description :A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026
VulnerabilitàAlta
CVE-2026-7054 - Tenda F456 httpd PPTPDClient fromPptpUserAdd buffer overflow

CVE ID :CVE-2026-7054 Published : April 26, 2026, 10:17 p.m. | 1 hour, 57 minutes ago Description :A weakness has been identified in Tenda F456 1.0.0.5. This vulnerability affects the function fromPptpUserAdd of the file /goform/PPTPDClient of the component httpd. Executing a manipulation of the argument opttype/usernamewith can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 apr 2026

Pagina 2071 di 3173

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.