Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

32953 risultati

News
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other ... Read more Published Date: Aug 12, 2026 (21 hours, 21 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33634

CVEfeed Newsroom22h fa
News
Adobe dicht dozijn kritieke ColdFusion-lekken: 'Zo snel mogelijk updaten'

Adobe dicht dozijn kritieke ColdFusion-lekken: 'Zo snel mogelijk updaten' Adobe heeft een belangrijke update voor een dozijn kritieke kwetsbaarheden in ColdFusion uitgebracht en roept organisaties op om die zo snel mogelijk te installeren. Het platform is geregeld het doelw ... Read more Published Date: Aug 12, 2026 (21 hours, 27 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom22h fa
News
Cisco waarschuwt voor actief misbruik van dos-lek in vpn-service firewalls

Cisco waarschuwt voor actief misbruik van dos-lek in vpn-service firewalls Cisco waarschuwt organisaties voor actief misbruik van een kwetsbaarheid in de vpn-service van ASA- en FTD-firewalls waardoor een denial of service ontstaat. Zo kunnen aanvallers de apparaten op afsta ... Read more Published Date: Aug 12, 2026 (21 hours, 38 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-20349

CVEfeed Newsroom22h fa
News
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE iden ... Read more Published Date: Aug 12, 2026 (21 hours, 54 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom23h fa
News
Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days

Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days Microsoft’s August 2026 Patch Tuesday release addresses roughly 400 security flaws across its products, including three Zero-days. One of the three is being actively exploited, while the other two wer ... Read more Published Date: Aug 12, 2026 (22 hours, 3 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-72971 CVE-2026-68820 CVE-2026-62832 CVE-2026-6727 CVE-2026-6726 CVE-2026-56291 CVE-2026-48939 CVE-2026-50656

CVEfeed Newsroom23h fa
News
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldB ... Read more Published Date: Aug 12, 2026 (22 hours, 44 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-72971 CVE-2026-68820 CVE-2026-62832 CVE-2026-50656

CVEfeed Newsroom23h fa
VulnerabilitàAlta
CVE-2026-66659 - WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability

CVE ID :CVE-2026-66659 Published : Aug. 12, 2026, 6:22 a.m. | 4 hours, 10 minutes ago Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-19594 - Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation

CVE ID :CVE-2026-19594 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 10 minutes ago Description :Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=` characters in query string values. An attacker with access to a downstream application built on snowflake.core could exploit the path traversal by supplying `..` as an object name, causing `snowflake.core` to issue REST requests against a parent resource or exploit the parameter pollution by injecting `&`/`#`/`=` into a free-form name field to override constraints on swap, clone, or rename operations — all executed under the application's privileged session. Successful exploitation requires the attacker to control an identifier or object-name string in an application built on snowflake.core that passes it to `snowflake.core` under a higher-privileged Snowflake session (e.g., an EXECUTE AS OWNER stored procedure, Streamlit app, or Native App). The fix is available in Snowflake Python API version 1.13.0, which also addresses several additional security findings. Users must manually upgrade. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-19073 - Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure

CVE ID :CVE-2026-19073 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 11 minutes ago Description :The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-19217 - Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget

CVE ID :CVE-2026-19217 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 11 minutes ago Description :The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-19052 - ProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls

CVE ID :CVE-2026-19052 Published : Aug. 12, 2026, 6:21 a.m. | 4 hours, 11 minutes ago Description :The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the ProSolution WP Client WordPress plugin before 2.0.9's activity records. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa
VulnerabilitàAlta
CVE-2026-18962 - WP Photo Album Plus < 9.2.09.002 - Subscriber+ Cross-Album File Upload via Missing Authorization

CVE ID :CVE-2026-18962 Published : Aug. 12, 2026, 6:20 a.m. | 4 hours, 11 minutes ago Description :The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator. Exploitation requires the WP Photo Album Plus WordPress plugin before 9.2.09.002's front-end user upload feature to be enabled, which is not the default. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE1g fa

Pagina 21 di 2747

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.