Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45463 risultati

VulnerabilitàAlta
CVE-2026-96559 - Rejected reason: This ID was for testing

CVE ID :CVE-2026-96559 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :Rejected reason: This ID was for testing Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96512 - Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization

CVE ID :CVE-2026-96512 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86679 - Broken Access Control vulnerability

CVE ID :CVE-2026-86679 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86681 - Broken Access Control vulnerability

CVE ID :CVE-2026-86681 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86683 - Broken Authentication Vulnerability

CVE ID :CVE-2026-86683 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86708 - Sensitive data exposure

CVE ID :CVE-2026-86708 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86678 - Broken Authentication vulnerability

CVE ID :CVE-2026-86678 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86677 - Broken Authentication vulnerability

CVE ID :CVE-2026-86677 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-18177 (CVSS 7.1)

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-18179 - IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities

CVE ID :CVE-2026-18179 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-59167 - SunEditor: Critical XSS vulnerability - sanitizer bypass

CVE ID :CVE-2026-59167 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, data exposure, or unauthorized browser-context actions. This issue is fixed in version 2.47.11. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-12974 - Security Policy Bypass in Forcepoint Security Engine (NGFW)

CVE ID :CVE-2026-12974 Published : Sept. 23, 2026, 2:17 p.m. | 25 minutes ago Description :A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0. Severity: 7.9 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 212 di 3789

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.