Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45460 risultati

VulnerabilitàAlta
CVE-2026-96672 - Frappe ERPNext before 16.34.1 Unauthorized Method Invocation

CVE ID :CVE-2026-96672 Published : Sept. 23, 2026, 3:35 p.m. | 53 minutes ago Description :Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and read their return values. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96600 - Isotope eCommerce through 2.9.10 SQL Injection via Backend Callbacks

CVE ID :CVE-2026-96600 Published : Sept. 23, 2026, 3:17 p.m. | 1 hour, 10 minutes ago Description :Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based injection payloads to extract arbitrary database contents including user password hashes from the tl_user table. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96599 - Isotope eCommerce through 2.9.10 Weak Order Identifier Generation

CVE ID :CVE-2026-96599 Published : Sept. 23, 2026, 3:17 p.m. | 1 hour, 10 minutes ago Description :Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to guess identifiers. Guest orders lack ownership verification, enabling attackers to access order details including billing address, customer information, and purchased files by supplying a guessed uid parameter. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96275 (CVSS 8.8)

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-96275 - Flatpak: flatpak: arbitrary write access as root via extra-data extraction

CVE ID :CVE-2026-96275 Published : Sept. 23, 2026, 3:17 p.m. | 1 hour, 10 minutes ago Description :A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96276 - Flatpak: flatpak: arbitrary write in host context via flatpak build-init

CVE ID :CVE-2026-96276 Published : Sept. 23, 2026, 3:17 p.m. | 1 hour, 10 minutes ago Description :If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-73587 - Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

CVE ID :CVE-2026-73587 Published : Sept. 23, 2026, 2:21 p.m. | 21 minutes ago Description :Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection mechanism bypass. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96611 - FFmpeg Signed Integer Overflow

CVE ID :CVE-2026-96611 Published : Sept. 23, 2026, 3:17 p.m. | 1 hour, 10 minutes ago Description :FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds checking, allowing values exceeding INT_MAX to become negative. In read_image_grid(), accumulating these values causes signed integer overflow (undefined behavior per C17 section 6.5), which on x86 wraps to a small positive value, bypassing downstream validity checks. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96560 - LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control Channel

CVE ID :CVE-2026-96560 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96512 - Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization

CVE ID :CVE-2026-96512 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96559 - Rejected reason: This ID was for testing

CVE ID :CVE-2026-96559 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :Rejected reason: This ID was for testing Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86708 - Sensitive data exposure

CVE ID :CVE-2026-86708 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 211 di 3789

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.