Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45447 risultati

VulnerabilitàAlta
CVE-2026-96513 (CVSS 7.3)

A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-93349 (CVSS 8.8)

Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-88832 (CVSS 7.3)

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-88830 (CVSS 7.5)

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-19179 (CVSS 8.2)

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-18875 (CVSS 7.3)

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.

NVD (NIST)23 set 2026
VulnerabilitàCritica
CVE-2026-18872 (CVSS 9.3)

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-18490 (CVSS 8.8)

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-18184 (CVSS 7.4)

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-18181 (CVSS 8.1)

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.

NVD (NIST)23 set 2026
News
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chai ... Read more Published Date: Sep 23, 2026 (4 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-86060 CVE-2026-67279 CVE-2026-67276

CVEfeed Newsroom23 set 2026
VulnerabilitàAlta
CVE-2026-6327 - Multiple Vulnerabilities in IBM Concert Software

CVE ID :CVE-2026-6327 Published : Sept. 23, 2026, 3:50 p.m. | 38 minutes ago Description :IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 208 di 3788

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.