Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38283 risultati

VulnerabilitàAlta
CVE-2026-4133 - TextP2P Texting Widget <= 1.7 - Cross-Site Request Forgery to Settings Update

CVE ID :CVE-2026-4133 Published : April 22, 2026, 9:16 a.m. | 51 minutes ago Description :The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.7. This is due to missing nonce validation in the imTextP2POptionPage() function which processes settings updates. The form at line 314 does not include a wp_nonce_field(), and the POST handler at line 7 does not call check_admin_referer() or wp_verify_nonce() before processing settings changes. This makes it possible for unauthenticated attackers to update all plugin settings including chat widget titles, messages, API credentials, colors, and reCAPTCHA configuration via a forged request, granted they can trick a site administrator into performing an action such as clicking a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-4138 - DX Unanswered Comments <= 1.7 - Cross-Site Request Forgery via Settings Update

CVE ID :CVE-2026-4138 Published : April 22, 2026, 9:16 a.m. | 51 minutes ago Description :The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation on the plugin's settings form in the dxuc-unanswered-comments-admin-page.php file. This makes it possible for unauthenticated attackers to modify plugin settings (dxuc_authors_list and dxuc_comment_count) via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-4139 - mCatFilter <= 0.5.2 - Cross-Site Request Forgery via compute_post() Function

CVE ID :CVE-2026-4139 Published : April 22, 2026, 9:16 a.m. | 51 minutes ago Description :The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is called in the plugin constructor on every page load via the plugins_loaded hook, and it directly processes $_POST data to modify plugin settings via update_option() without any CSRF token validation. This makes it possible for unauthenticated attackers to modify all plugin settings, including category exclusion rules, feed exclusion flags, and tag page exclusion flags, via a forged POST request, granted they can trick a site administrator into performing an action such as clicking a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-4140 - Ni WooCommerce Order Export <= 3.1.6 - Cross-Site Request Forgery to Settings Update via ni_order_export_action AJAX Action

CVE ID :CVE-2026-4140 Published : April 22, 2026, 9:16 a.m. | 51 minutes ago Description :The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.1.6. This is due to missing nonce validation in the ni_order_export_action() AJAX handler function. The handler processes settings updates when the 'page' parameter is set to 'nioe-order-settings', delegating to Ni_Order_Setting::page_ajax() which calls update_option('ni_order_export_option', $_REQUEST) without verifying any nonce or checking user capabilities. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request, granted they can trick a site administrator into performing an action such as clicking a link. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàCritica
CVE-2026-4119 (CVSS 9.1)

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_add_table) and deleting tables (admin_post_delete_db_table) without implementing any capability checks via current_user_can() or nonce verification via wp_verify_nonce()/check_admin_referer(). The admin_post hook only requires the user to be logged in, meaning any authenticated user including Subscribers can access these endpoints. The cdbt_delete_db_table() function takes a user-supplied table name from $_POST['db_table'] and executes a DROP TABLE SQL query, allowing any authenticated attacker to delete any database table including critical WordPress core tables such as wp_users or wp_options. The cdbt_create_new_table() function similarly allows creating arbitrary tables. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary database tables and delete any existing database table, potentially destroying the entire WordPress installation.

NVD (NIST)22 apr 2026
News
1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online

1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online A critical spoofing vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-32201, remains unpatched on over 1,370 internet-facing IP addresses worldwide, according to fresh scanning data fr ... Read more Published Date: Apr 22, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32201 CVE-2025-49706 CVE-2025-49704

CVEfeed Newsroom22 apr 2026
News
Command Injection Vulnerability (CVE-2025-29635) Exploited in the Wild

Command Injection Vulnerability (CVE-2025-29635) Exploited in the Wild The Akamai Security Intelligence and Response Team (SIRT) has issued a warning regarding a surge in malicious activity targeting end-of-life networking hardware. According to a new report, threat acto ... Read more Published Date: Apr 22, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33626 CVE-2026-33825 CVE-2026-22679 CVE-2026-22755 CVE-2025-29635

CVEfeed Newsroom22 apr 2026
News
March 2026 Cyber Threat Landscape Fueled by Ransomware, Breaches, and Access Markets

March 2026 Cyber Threat Landscape Fueled by Ransomware, Breaches, and Access Markets The 2026 threat landscape continued to intensify in March, with ransomware attacks, expanding data breach activity, and a growing underground market for compromised access shaping the global cybersecu ... Read more Published Date: Apr 22, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33017 CVE-2026-20131 CVE-2026-20963 CVE-2025-53521 CVE-2021-22681

CVEfeed Newsroom22 apr 2026
News
CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server

CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could ex ... Read more Published Date: Apr 22, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-40050

CVEfeed Newsroom22 apr 2026
VulnerabilitàAlta
CVE-2026-6842 - Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions

CVE ID :CVE-2026-6842 Published : April 22, 2026, 7:34 a.m. | 33 minutes ago Description :A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed. Severity: 2.5 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-6840 - Apache Airflow Operator Code Injection Vulnerability

CVE ID :CVE-2026-6840 Published : April 22, 2026, 7:16 a.m. | 51 minutes ago Description :Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026
VulnerabilitàAlta
CVE-2026-6839 - Samsung Open Source ONE Out-of-Bounds Access Vulnerability

CVE ID :CVE-2026-6839 Published : April 22, 2026, 7:16 a.m. | 51 minutes ago Description :Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE Affected version is prior to commit 1.30.0. Severity: 6.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 apr 2026

Pagina 2142 di 3191

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.