News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38326 risultati
CVE ID :CVE-2026-39467 Published : April 21, 2026, 10:16 a.m. | 1 hour, 49 minutes ago Description :Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-13826 Published : April 21, 2026, 9:16 a.m. | 2 hours, 49 minutes ago Description :Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vulnerability is caused by inadequate validation of user-supplied input. An attacker can exploit this vulnerability by sending malicious requests. If the vulnerability is successfully exploited, the application can be made to stop responding, resulting in a DoS condition. It is possible to manually restart the application. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Nexcorium Botnet Turns Unpatched DVRs into DDoS Foot Soldiers Security researchers at FortiGuard Labs have uncovered a sophisticated campaign deploying Nexcorium, a multi-architecture Mirai variant that turns unpatched digital video recorders (DVRs) into foot so ... Read more Published Date: Apr 21, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22679 CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2025-32975 CVE-2025-48700 CVE-2025-2749 CVE-2024-3721 CVE-2024-27199 CVE-2023-27351 CVE-2017-17215
CVE ID :CVE-2026-3317 Published : April 21, 2026, 10:16 a.m. | 1 hour, 49 minutes ago Description :Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript code in the victim's browser. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA Adds 8 Exploited Vulnerabilities Affecting Cisco, Zimbra, TeamCity The Cybersecurity and Infrastructure Security Agency (CISA) have expanded its Known Exploited Vulnerabilities, commonly referred to as the KEV catalog, with eight newly identified security flaws that ... Read more Published Date: Apr 21, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2025-32975 CVE-2025-48700 CVE-2025-2749 CVE-2024-27199 CVE-2024-27198 CVE-2023-27351
CVE ID :CVE-2026-31369 Published : April 21, 2026, 7:16 a.m. | 4 hours, 49 minutes ago Description :PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability Severity: 3.2 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6712 Published : April 21, 2026, 7:16 a.m. | 4 hours, 49 minutes ago Description :The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6711 Published : April 21, 2026, 7:16 a.m. | 4 hours, 49 minutes ago Description :The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.6. This is due to the use of filter_input() without a sanitization filter and insufficient output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrator into performing an action such as clicking on a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-6703 Published : April 21, 2026, 7:16 a.m. | 4 hours, 49 minutes ago Description :The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global site-wide plugin configuration options, including toggling custom CSS, disabling blocks, changing layout defaults such as content width, container padding, and container gap, and altering auto-block-recovery behavior. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-31370 Published : April 21, 2026, 7:16 a.m. | 4 hours, 49 minutes ago Description :Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-31368 Published : April 21, 2026, 7:16 a.m. | 4 hours, 49 minutes ago Description :AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws impacting Cisco C ... Read more Published Date: Apr 21, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197 CVE-2026-33032 CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2025-32975 CVE-2025-48700 CVE-2025-2749 CVE-2024-27199 CVE-2024-27198 CVE-2023-27351
Pagina 2166 di 3194