Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38140 risultati

VulnerabilitàAlta
CVE-2026-1952 - Denial of service via the undocumented subfunction in AS320T

CVE ID :CVE-2026-1952 Published : April 24, 2026, 7:16 a.m. | 6 hours, 55 minutes ago Description :Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
VulnerabilitàAlta
CVE-2026-1950 - No checking of the length of the buffer with the file name in AS320T

CVE ID :CVE-2026-1950 Published : April 24, 2026, 7:16 a.m. | 6 hours, 55 minutes ago Description :Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
News
AI in the Driver’s Seat: How the ‘Bissa’ Scanner Hijacked 900+ Firms in Weeks

AI in the Driver’s Seat: How the ‘Bissa’ Scanner Hijacked 900+ Firms in Weeks Image: The DFIR Report Researchers from The DFIR Report recently discovered an exposed command-and-control server that provided a rare look into a massive, AI-assisted exploitation campaign. The opera ... Read more Published Date: Apr 24, 2026 (3 days, 7 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom24 apr 2026
VulnerabilitàAlta
CVE-2026-5364 (CVSS 8.1)

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than being restricted to administrator-configured values, which when combined with the fact that validation occurs on the unsanitized extension while the file is saved with a sanitized extension, allows special characters like '$' to be stripped during the save process. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and potentially achieve remote code execution, however, an .htaccess file and name randomization is in place which restricts real-world exploitability.

NVD (NIST)24 apr 2026
VulnerabilitàAlta
CVE-2026-5364 - Drag and Drop File Upload for Contact Form 7 <= 1.1.3 - Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass

CVE ID :CVE-2026-5364 Published : April 24, 2026, 6:16 a.m. | 7 hours, 55 minutes ago Description :The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than being restricted to administrator-configured values, which when combined with the fact that validation occurs on the unsanitized extension while the file is saved with a sanitized extension, allows special characters like '$' to be stripped during the save process. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and potentially achieve remote code execution, however, an .htaccess file and name randomization is in place which restricts real-world exploitability. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
VulnerabilitàAlta
CVE-2026-1949 - Incorrect calculation of buffer size on the stack in AS320T

CVE ID :CVE-2026-1949 Published : April 24, 2026, 6:16 a.m. | 5 hours, 55 minutes ago Description :Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
VulnerabilitàAlta
CVE-2026-6810 - Booking Calendar Contact Form <= 1.2.63 - Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover

CVE ID :CVE-2026-6810 Published : April 24, 2026, 6:16 a.m. | 7 hours, 55 minutes ago Description :The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to takeover other user's calendars and view user data associated with the calendar. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
VulnerabilitàAlta
CVE-2026-5347 - WP Books Gallery <= 4.8.0 - Missing Authorization to Unauthenticated Settings Update via 'permalink_structure' Parameter

CVE ID :CVE-2026-5347 Published : April 24, 2026, 6:16 a.m. | 5 hours, 55 minutes ago Description :The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of capability checks and nonce verification in the admin_init hook that handles the permalink settings update at line 205-209 of wp-books-gallery.php. The vulnerable code checks only for the presence of the 'permalink_structure' POST parameter before updating the 'wbg_cpt_slug' option, without verifying that the request comes from an authenticated administrator. This makes it possible for unauthenticated attackers to modify the custom post type slug for the books gallery, which changes the URL structure for all book entries and can break existing links and SEO rankings. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
VulnerabilitàAlta
CVE-2026-5428 - Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field

CVE ID :CVE-2026-5428 Published : April 24, 2026, 6:16 a.m. | 7 hours, 55 minutes ago Description :The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of esc_attr() for the alt attribute context. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page with the malicious image displayed in the media grid widget. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026
News
The Notification Trap: How Apple’s New iOS Patch Blocks Forensic Recovery of “Deleted” Signal Messages

The Notification Trap: How Apple’s New iOS Patch Blocks Forensic Recovery of “Deleted” Signal Messages Apple recently disseminated the iOS 26.4.2 update for compatible devices, primarily to remediate the vulnerability designated as CVE-2026-28950. This security flaw pertains to a method by which the FB ... Read more Published Date: Apr 24, 2026 (3 days, 9 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom24 apr 2026
VulnerabilitàAlta
CVE-2026-6947 (CVSS 7.5)

DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform brute-force attacks to gain control over the device.

NVD (NIST)24 apr 2026
VulnerabilitàAlta
CVE-2026-6947 - D-Link|DWM-222W USB Wi-Fi Adapter - Brute-Force Protection Bypass

CVE ID :CVE-2026-6947 Published : April 24, 2026, 4:16 a.m. | 7 hours, 55 minutes ago Description :DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform brute-force attacks to gain control over the device. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 apr 2026

Pagina 2097 di 3179

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.