Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45464 risultati

VulnerabilitàAlta
CVE-2026-91808 - Foxit PDF Editor/Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

CVE ID :CVE-2026-91808 Published : Sept. 23, 2026, 8:17 a.m. | 28 minutes ago Description :A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91799 - Foxit Editor/Reader Array resetForm Use-After-Free Vulnerability

CVE ID :CVE-2026-91799 Published : Sept. 23, 2026, 8:17 a.m. | 28 minutes ago Description :A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in application crashes or arbitrary code execution. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91797 - Foxit PDF Editor/Reader Portfolio Directory Traversal Remote Code Execution Vulnerability

CVE ID :CVE-2026-91797 Published : Sept. 23, 2026, 8:17 a.m. | 28 minutes ago Description :Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91798 - Foxit PDF Editor/Reader Updater Privilege Escalation

CVE ID :CVE-2026-91798 Published : Sept. 23, 2026, 8:17 a.m. | 28 minutes ago Description :A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
News
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk ap ... Read more Published Date: Sep 23, 2026 (4 days ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom23 set 2026
VulnerabilitàAlta
CVE-2026-93528 - NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request Page

CVE ID :CVE-2026-93528 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-93510 - Points and Rewards for WooCommerce < 2.10.4 - Subscriber+ Arbitrary Points and Wallet Balance Manipulation via assign_claim_points

CVE ID :CVE-2026-93510 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a companion wallet Points and Rewards for WooCommerce WordPress plugin before 2.10.4 is active, wallet balance. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-93511 - Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification Bypass

CVE ID :CVE-2026-93511 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events against any order whose transaction id they know. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-93508 - WC Fields Factory < 4.1.11 - Subscriber+ Arbitrary Post Meta Manipulation via AJAX

CVE ID :CVE-2026-93508 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-93507 - WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content Disclosure

CVE ID :CVE-2026-93507 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91024 - Booking Manager < 2.1.21 - Author+ SQLi via ICS Import Feed UID (sync_gid)

CVE ID :CVE-2026-91024 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-91025 - Booking Manager < 2.1.21 - Subscriber+ Arbitrary User Plugin Meta Modification via IDOR

CVE ID :CVE-2026-91025 Published : Sept. 23, 2026, 6:17 a.m. | 20 minutes ago Description :The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking Manager WordPress plugin before 2.1.21's per-user settings on arbitrary users, including administrators. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 220 di 3789

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.