News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38532 risultati
Kritieke kwetsbaarheid in Nginx UI - CVE-2026-33032 Een kritieke kwetsbaarheid in Nginx UI maakt het mogelijk voor aanvallers om Nginx servers (die gebruik maken van Nginx UI) op afstand over te nemen. Nginx UI is een webgebaseerde managementinterface ... Read more Published Date: Apr 16, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-33032
The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versions up to, and including, 1.6. This is due to missing nonce validation and insufficient file path validation on the delete action in the 'appform_options_page_html' function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.
CISA meldt actief misbruik van Windows kwetsbaarheid Een kwetsbaarheid in Windows waardoor een aanvaller die al toegang tot een systeem heeft zijn rechten kan verhogen wordt actief misbruikt, zo meldt het Cybersecurity and Infrastructure Security Agency ... Read more Published Date: Apr 16, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-33032 CVE-2025-60710
Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks A critical security vulnerability has been officially disclosed, affecting multiple versions of Enterprise and Cloud platforms. Tracked as CVE-2026-20204, this high-severity flaw carries a CVSS score ... Read more Published Date: Apr 16, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-20204
Critical Chrome Vulnerabilities Let Attackers Execute Arbitrary Code – Update Now! Google has rolled out a crucial security update for its Chrome browser, addressing 31 vulnerabilities that could leave systems exposed to severe cyber threats. Released on April 15, 2026, this Stable ... Read more Published Date: Apr 16, 2026 (23 hours, 15 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-6358 CVE-2026-6299 CVE-2026-6298 CVE-2026-6297 CVE-2026-6296
CVE ID :CVE-2026-0718 Published : April 16, 2026, 8:16 a.m. | 5 hours, 41 minutes ago Description :The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ultp_shareCount_callback() function in all versions up to, and including, 5.0.5. This makes it possible for unauthenticated attackers to modify the share_count post meta for any post, including private or draft posts. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-14868 Published : April 16, 2026, 8:16 a.m. | 5 hours, 41 minutes ago Description :The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versions up to, and including, 1.6. This is due to missing nonce validation and insufficient file path validation on the delete action in the 'appform_options_page_html' function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41035 Published : April 16, 2026, 7:16 a.m. | 6 hours, 41 minutes ago Description :In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismatic_decode' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page by submitting a comment containing a crafted 'prismatic_encoded' pseudo-shortcode.
CVE ID :CVE-2026-3861 Published : April 16, 2026, 7:16 a.m. | 6 hours, 41 minutes ago Description :LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs, potentially causing the iOS device to become temporarily inoperable. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41034 Published : April 16, 2026, 7:16 a.m. | 6 hours, 41 minutes ago Description :ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-41030 Published : April 16, 2026, 7:16 a.m. | 6 hours, 41 minutes ago Description :In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2236 di 3211