Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38505 risultati

VulnerabilitàAlta
CVE-2026-6577 (CVSS 7.3)

A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)19 apr 2026
VulnerabilitàAlta
CVE-2026-6577 - liangliangyy DjangoBlog logtracks Endpoint views.py missing authentication

CVE ID :CVE-2026-6577 Published : April 19, 2026, 8:16 p.m. | 7 hours, 9 minutes ago Description :A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 apr 2026
VulnerabilitàAlta
CVE-2026-6576 - liangliangyy DjangoBlog WeChat Bot commonapi.py CommandHandler command injection

CVE ID :CVE-2026-6576 Published : April 19, 2026, 7:16 p.m. | 8 hours, 9 minutes ago Description :A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the component WeChat Bot Interface. Executing a manipulation of the argument Source can lead to command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 apr 2026
News
Dgraph’s Debug Endpoint Hands Over Admin Tokens to Anyone

Dgraph’s Debug Endpoint Hands Over Admin Tokens to Anyone Dgraph, the horizontally scalable and distributed GraphQL database known for its ACID transactions and graph-backend performance, is facing a significant security challenge. A recently disclosed criti ... Read more Published Date: Apr 19, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-40173 CVE-2026-22679 CVE-2026-33976

CVEfeed Newsroom19 apr 2026
VulnerabilitàAlta
CVE-2026-6574 (CVSS 7.3)

A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)19 apr 2026
VulnerabilitàAlta
CVE-2026-6574 - osuuu LightPicture API Upload Endpoint lp.sql hard-coded credentials

CVE ID :CVE-2026-6574 Published : April 19, 2026, 2:16 p.m. | 13 hours, 9 minutes ago Description :A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 apr 2026
VulnerabilitàAlta
CVE-2026-6573 - PHPEMS Instant Exam Creation exams.master.php temppage server-side request forgery

CVE ID :CVE-2026-6573 Published : April 19, 2026, 1:16 p.m. | 14 hours, 9 minutes ago Description :A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server-side request forgery. The attack can be executed remotely. The exploit is now public and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 apr 2026
VulnerabilitàAlta
CVE-2026-6571 - kodcloud KodExplorer systemRole.class.php roleGroupAction authorization

CVE ID :CVE-2026-6571 Published : April 19, 2026, 12:16 p.m. | 13 hours, 9 minutes ago Description :A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 apr 2026
VulnerabilitàAlta
CVE-2026-6570 - kodcloud KodExplorer systemMember.class.php initInstall authorization

CVE ID :CVE-2026-6570 Published : April 19, 2026, 12:16 p.m. | 13 hours, 9 minutes ago Description :A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 apr 2026
VulnerabilitàAlta
CVE-2026-6572 - Collabora KodExplorer fileUpload Endpoint share.class.php improper authorization

CVE ID :CVE-2026-6572 Published : April 19, 2026, 1:16 p.m. | 14 hours, 9 minutes ago Description :A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app/controller/share.class.php of the component fileUpload Endpoint. The manipulation of the argument fileUpload leads to improper authorization. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitation is known to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 apr 2026
VulnerabilitàAlta
CVE-2026-6569 (CVSS 7.3)

A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)19 apr 2026
VulnerabilitàAlta
CVE-2026-6569 - kodcloud KodExplorer fileGet Endpoint share.class.php improper authentication

CVE ID :CVE-2026-6569 Published : April 19, 2026, 11:16 a.m. | 14 hours, 9 minutes ago Description :A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE19 apr 2026

Pagina 2204 di 3209

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.