Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45460 risultati

VulnerabilitàAlta
CVE-2026-6327 - Multiple Vulnerabilities in IBM Concert Software

CVE ID :CVE-2026-6327 Published : Sept. 23, 2026, 3:50 p.m. | 38 minutes ago Description :IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-93769 - HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover

CVE ID :CVE-2026-93769 Published : Sept. 23, 2026, 3:49 p.m. | 38 minutes ago Description :HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-4921 - IBM Guardium Data Protection is affected by multiple vulnerabilities.

CVE ID :CVE-2026-4921 Published : Sept. 23, 2026, 3:49 p.m. | 38 minutes ago Description :IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. Severity: 2.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-3626 - Multiple Vulnerabilities in IBM Concert Software

CVE ID :CVE-2026-3626 Published : Sept. 23, 2026, 3:49 p.m. | 38 minutes ago Description :IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-19267 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE ID :CVE-2026-19267 Published : Sept. 23, 2026, 3:49 p.m. | 39 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-19087 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE ID :CVE-2026-19087 Published : Sept. 23, 2026, 3:48 p.m. | 40 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-18505 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE ID :CVE-2026-18505 Published : Sept. 23, 2026, 3:46 p.m. | 42 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-18185 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE ID :CVE-2026-18185 Published : Sept. 23, 2026, 3:44 p.m. | 43 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-18180 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE ID :CVE-2026-18180 Published : Sept. 23, 2026, 3:42 p.m. | 45 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96675 - alsa-lib through 1.2.16.1 Denial of Service via pcm_multi

CVE ID :CVE-2026-96675 Published : Sept. 23, 2026, 3:35 p.m. | 53 minutes ago Description :alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96674 - alsa-lib through 1.2.16.1 Integer Overflow via Topology File

CVE ID :CVE-2026-96674 Published : Sept. 23, 2026, 3:35 p.m. | 53 minutes ago Description :alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96673 - Photoview through 2.4.0 SQL Injection via album download route

CVE ID :CVE-2026-96673 Published : Sept. 23, 2026, 3:35 p.m. | 53 minutes ago Description :Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 210 di 3789

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.