Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38532 risultati

VulnerabilitàAlta
CVE-2025-15621 - Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication

CVE ID :CVE-2025-15621 Published : April 16, 2026, 1:16 p.m. | 41 minutes ago Description :Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
News
Critical 9.1 Bypass in OAuth2 Proxy Exposes Upstream Resources

Critical 9.1 Bypass in OAuth2 Proxy Exposes Upstream Resources In the world of cloud-native security, OAuth2 Proxy serves as a vital gatekeeper, providing a flexible and open-source way to protect web applications with OAuth2 and OIDC authentication. However, a n ... Read more Published Date: Apr 16, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-34457 CVE-2026-38526 CVE-2026-22679 CVE-2026-33032 CVE-2026-30849 CVE-2026-22731

CVEfeed Newsroom16 apr 2026
News
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories

ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories You know that feeling when you open your feed on a Thursday morning and it's just... a lot? Yeah. This week delivered. We've got hackers getting creative in ways that are almost impressive if you igno ... Read more Published Date: Apr 16, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-33825 CVE-2026-26151 CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2025-55182 CVE-2009-0238

CVEfeed Newsroom16 apr 2026
News
Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)

Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808) Two vulnerabilities (CVE-2026-39813, CVE-2026-39808) in FortiSandbox could be leveraged by unauthenticated attackers to bypass authentication and execute unauthorized code or commands on vulnerable sy ... Read more Published Date: Apr 16, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-39813 CVE-2026-39812 CVE-2026-39808 CVE-2026-25691 CVE-2025-61886

CVEfeed Newsroom16 apr 2026
News
CVE-2026-38526: Critical CVSS 10 Vulnerability Discovered in Krayin CRM

CVE-2026-38526: Critical CVSS 10 Vulnerability Discovered in Krayin CRM A maximum-severity security flaw has been unearthed in Krayin CRM, a popular open-source framework built on Laravel and Vue.js. The vulnerability, tracked as CVE-2026-38526, carries a CVSS score of 10 ... Read more Published Date: Apr 16, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom16 apr 2026
VulnerabilitàAlta
CVE-2026-3489 (CVSS 7.5)

The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, and including, 3.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)16 apr 2026
News
CVE-2026-40884: Critical 9.8 Bypass Hits goshs SFTP Servers

CVE-2026-40884: Critical 9.8 Bypass Hits goshs SFTP Servers In the fast-paced environment of penetration testing and CTF challenges, tools that prioritize speed and ease of use are invaluable. However, a critical security vulnerability has been identified in g ... Read more Published Date: Apr 16, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom16 apr 2026
News
Critical Cisco ISE Vulnerabilities Let Remote Attackers Execute Malicious Code

Critical Cisco ISE Vulnerabilities Let Remote Attackers Execute Malicious Code Cisco has issued an urgent security advisory warning of multiple vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). According to the official Cisco sec ... Read more Published Date: Apr 16, 2026 (23 hours, 24 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-20148 CVE-2026-20147

CVEfeed Newsroom16 apr 2026
News
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution

Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution Cisco has announced patches to address four critical security flaws impacting Identity Services and Webex Services that could result in arbitrary code execution and allow an attacker to impersonate an ... Read more Published Date: Apr 16, 2026 (23 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-20186 CVE-2026-20184 CVE-2026-20180 CVE-2026-20147 CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2025-55182

CVEfeed Newsroom16 apr 2026
VulnerabilitàAlta
CVE-2026-3155 - OneSignal – Web Push Notifications <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion via 'post_id'

CVE ID :CVE-2026-3155 Published : April 16, 2026, 12:16 p.m. | 1 hour, 42 minutes ago Description :The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete OneSignal metadata for arbitrary posts. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-3489 - DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages'

CVE ID :CVE-2026-3489 Published : April 16, 2026, 11:21 a.m. | 36 minutes ago Description :The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, and including, 3.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-3369 - Better Find and Replace – AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title

CVE ID :CVE-2026-3369 Published : April 16, 2026, 12:16 p.m. | 1 hour, 42 minutes ago Description :The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026

Pagina 2234 di 3211

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.