Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38343 risultati

VulnerabilitàAlta
CVE-2026-6629 (CVSS 7.3)

A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file sql.jsp of the component Interface. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)20 apr 2026
VulnerabilitàAlta
CVE-2026-6629 - Metasoft 美特软件 MetaCRM Interface sql.jsp Statement.executeUpdate sql injection

CVE ID :CVE-2026-6629 Published : April 20, 2026, 11:16 a.m. | 2 hours, 10 minutes ago Description :A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file sql.jsp of the component Interface. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
News
Vulnerability in GNU sed software

Vulnerability in GNU sed software Vulnerability in GNU sed software CVE ID CVE-2026-5958 Publication date 20 April 2026 Vendor GNU Product sed Vulnerable versions From 4.1e below 4.10 Vulnerability type (CWE) Time-of-check Time-of-use ... Read more Published Date: Apr 20, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5958

CVEfeed Newsroom20 apr 2026
News
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain

Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain Cybersecurity researchers have discovered a critical "by design" weakness in the Model Context Protocol's (MCP) architecture that could pave the way for remote code execution and have a cascading effe ... Read more Published Date: Apr 20, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom20 apr 2026
News
Aanvallen op end-of-life TP-Link routers via oude kwetsbaarheid

Aanvallen op end-of-life TP-Link routers via oude kwetsbaarheid TP-Link-routers worden actief aangevallen via een kwetsbaarheid uit 2023, zo stelt securitybedrijf Palo Alto Networks. Het gaat om end-of-life modellen van TP-Link waarvoor geen updates meer beschikb ... Read more Published Date: Apr 20, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2023-33538

CVEfeed Newsroom20 apr 2026
VulnerabilitàAlta
CVE-2026-6628 - phili67 Ecclesia CRM Query Viewer view ValidateInput sql injection

CVE ID :CVE-2026-6628 Published : April 20, 2026, 10:16 a.m. | 3 hours, 10 minutes ago Description :A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query Viewer Component. This manipulation of the argument custom causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6625 (CVSS 7.3)

A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)20 apr 2026
VulnerabilitàAlta
CVE-2026-6622 - BichitroGan ISP Billing Software Customer edit cross site scripting

CVE ID :CVE-2026-6622 Published : April 20, 2026, 10:16 a.m. | 3 hours, 10 minutes ago Description :A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6623 - BichitroGan ISP Billing Software Profile users-view cross site scripting

CVE ID :CVE-2026-6623 Published : April 20, 2026, 10:16 a.m. | 3 hours, 10 minutes ago Description :A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6625 - moxi624 Mogu Blog v2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadPictureByUrl server-side request forgery

CVE ID :CVE-2026-6625 Published : April 20, 2026, 10:16 a.m. | 3 hours, 10 minutes ago Description :A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6626 - Cockpit-HQ Cockpit Asset Handler/Aggregate data query logic injection

CVE ID :CVE-2026-6626 Published : April 20, 2026, 10:16 a.m. | 3 hours, 10 minutes ago Description :A vulnerability was detected in Cockpit-HQ Cockpit up to 2.13.5. Affected by this issue is some unknown functionality of the component Asset Handler/Aggregate Handler. The manipulation results in improper neutralization of special elements in data query logic. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026
VulnerabilitàAlta
CVE-2026-6624 - BichitroGan ISP Billing Software Pool List add cross site scripting

CVE ID :CVE-2026-6624 Published : April 20, 2026, 10:16 a.m. | 3 hours, 10 minutes ago Description :A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the file /?\_route=pool/add of the component Pool List Interface. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 apr 2026

Pagina 2182 di 3196

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.