Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45463 risultati

VulnerabilitàAlta
CVE-2026-88974 - WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost

CVE ID :CVE-2026-88974 Published : Sept. 23, 2026, 2:11 p.m. | 31 minutes ago Description :WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-73586 - Dell Secure Connect Gateway Insufficient Session Expiration Vulnerability

CVE ID :CVE-2026-73586 Published : Sept. 23, 2026, 2:10 p.m. | 32 minutes ago Description :Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and Unauthorized access. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-63000 - REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates

CVE ID :CVE-2026-63000 Published : Sept. 23, 2026, 2:08 p.m. | 33 minutes ago Description :REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/install/lib/api/api_package_update.php inherits the false default from rex_api_function::requiresCsrfProtection() instead of requiring a CSRF token. An unauthenticated attacker can cause a logged-in administrator's browser to request a selected package update from the configured REDAXO package server, changing installed addon code or disrupting the site without the administrator's intent. This issue is fixed in version 5.21.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96609 - Robur Albatross Ring Buffer Denial of Service Vulnerability

CVE ID :CVE-2026-96609 Published : Sept. 23, 2026, 3:17 p.m. | 1 hour, 10 minutes ago Description :Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users who can send console subscription commands to unikernels that produce sufficient log output to fill the ring buffer (1024 lines). It is not exploitable by unauthorized clients. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-62998 - REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration

CVE ID :CVE-2026-62998 Published : Sept. 23, 2026, 2:07 p.m. | 35 minutes ago Description :REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested column. An authenticated backend user can make prepareQuery() add an escaped but unauthorized ORDER BY identifier, allowing error-based enumeration of columns in joined tables and ordering by unselected sensitive fields such as rex_user.password. This issue is fixed in version 5.21.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-63002 - REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames

CVE ID :CVE-2026-63002 Published : Sept. 23, 2026, 2:05 p.m. | 36 minutes ago Description :REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page without rex_escape(). An attacker who can place an unregistered file with HTML metacharacters in the media directory can execute script in the browser of a backend user with media[sync] permission when that user opens the Sync page, enabling session theft or unauthorized backend actions. This issue is fixed in version 5.21.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-71178 - Dell Secure Connect Gateway Policy Manager Improper Authorization Vulnerability

CVE ID :CVE-2026-71178 Published : Sept. 23, 2026, 2:05 p.m. | 37 minutes ago Description :Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-63001 - REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`

CVE ID :CVE-2026-63001 Published : Sept. 23, 2026, 2:03 p.m. | 39 minutes ago Description :REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backend warning HTML without escaping it when invoked through MEDIA_IS_IN_USE. An administrator with Media Manager access can store HTML in a type name, and the payload executes in another administrator's browser when that administrator tries to delete media referenced by the type's effects, enabling session theft or unauthorized backend actions. This issue is fixed in version 5.21.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-71177 - Dell Secure Connect Gateway Improper Restriction of Rendered UI Layers or Frames Vulnerability

CVE ID :CVE-2026-71177 Published : Sept. 23, 2026, 2:02 p.m. | 39 minutes ago Description :Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-61834 - scim-patch: Mutation of Inherited Built-in Method Objects

CVE ID :CVE-2026-61834 Published : Sept. 23, 2026, 2:02 p.m. | 40 minutes ago Description :scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and assign() uses prototype-chain membership checks while resolving attacker-controlled SCIM PATCH paths. A path or one of the dotted value keys beginning with an inherited property such as toString can therefore traverse into a shared built-in function object and add attacker-controlled properties, causing process-global mutation that may affect application logic reading inherited-method properties. This issue is fixed in version 0.9.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
News
Check Point waarschuwt voor Path Traversal kwetsbaarheid

Check Point waarschuwt voor Path Traversal kwetsbaarheid Check Point waarschuwt voor een Path Traversal en File Upload kwetsbaarheid in de Check Point Management Server. Met behulp van deze kwetsbaarheid (CVE 2026 93616) kunnen aanvallers, zonder enige vorm ... Read more Published Date: Sep 23, 2026 (4 days, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-93616

CVEfeed Newsroom23 set 2026
News
Vulnerability in WEBCON BPS software

Vulnerability in WEBCON BPS software Vulnerability in WEBCON BPS software CVE ID CVE-2026-92419 Publication date 23 September 2026 Vendor WEBCON Product WEBCON BPS Vulnerable versions From 2024.1.1.145 before 2025.2.1.177From 2026.1.1.1 ... Read more Published Date: Sep 23, 2026 (4 days, 23 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom23 set 2026

Pagina 213 di 3789

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.