Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38532 risultati

News
Kritieke kwetsbaarheid in Nginx UI - CVE-2026-33032

Kritieke kwetsbaarheid in Nginx UI - CVE-2026-33032 Een kritieke kwetsbaarheid in Nginx UI maakt het mogelijk voor aanvallers om Nginx servers (die gebruik maken van Nginx UI) op afstand over te nemen. Nginx UI is een webgebaseerde managementinterface ... Read more Published Date: Apr 16, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-33032

CVEfeed Newsroom16 apr 2026
VulnerabilitàAlta
CVE-2025-14868 (CVSS 8.8)

The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versions up to, and including, 1.6. This is due to missing nonce validation and insufficient file path validation on the delete action in the 'appform_options_page_html' function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

NVD (NIST)16 apr 2026
News
CISA meldt actief misbruik van Windows kwetsbaarheid

CISA meldt actief misbruik van Windows kwetsbaarheid Een kwetsbaarheid in Windows waardoor een aanvaller die al toegang tot een systeem heeft zijn rechten kan verhogen wordt actief misbruikt, zo meldt het Cybersecurity and Infrastructure Security Agency ... Read more Published Date: Apr 16, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-33032 CVE-2025-60710

CVEfeed Newsroom16 apr 2026
News
Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks

Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks A critical security vulnerability has been officially disclosed, affecting multiple versions of Enterprise and Cloud platforms. Tracked as CVE-2026-20204, this high-severity flaw carries a CVSS score ... Read more Published Date: Apr 16, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-20204

CVEfeed Newsroom16 apr 2026
News
Critical Chrome Vulnerabilities Let Attackers Execute Arbitrary Code – Update Now!

Critical Chrome Vulnerabilities Let Attackers Execute Arbitrary Code – Update Now! Google has rolled out a crucial security update for its Chrome browser, addressing 31 vulnerabilities that could leave systems exposed to severe cyber threats. Released on April 15, 2026, this Stable ... Read more Published Date: Apr 16, 2026 (23 hours, 15 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-6358 CVE-2026-6299 CVE-2026-6298 CVE-2026-6297 CVE-2026-6296

CVEfeed Newsroom16 apr 2026
VulnerabilitàAlta
CVE-2026-0718 - Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification

CVE ID :CVE-2026-0718 Published : April 16, 2026, 8:16 a.m. | 5 hours, 41 minutes ago Description :The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ultp_shareCount_callback() function in all versions up to, and including, 5.0.5. This makes it possible for unauthenticated attackers to modify the share_count post meta for any post, including private or draft posts. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2025-14868 - Career Section <= 1.6 - Cross-Site Request Forgery to Arbitrary File Deletion

CVE ID :CVE-2025-14868 Published : April 16, 2026, 8:16 a.m. | 5 hours, 41 minutes ago Description :The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versions up to, and including, 1.6. This is due to missing nonce validation and insufficient file path validation on the delete action in the 'appform_options_page_html' function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-41035 - "Rsync Use-After-Free Vulnerability"

CVE ID :CVE-2026-41035 Published : April 16, 2026, 7:16 a.m. | 6 hours, 41 minutes ago Description :In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-3876 (CVSS 7.2)

The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismatic_decode' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page by submitting a comment containing a crafted 'prismatic_encoded' pseudo-shortcode.

NVD (NIST)16 apr 2026
VulnerabilitàAlta
CVE-2026-3861 - LINE iOS Dialog Flood Vulnerability

CVE ID :CVE-2026-3861 Published : April 16, 2026, 7:16 a.m. | 6 hours, 41 minutes ago Description :LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs, potentially causing the iOS device to become temporarily inoperable. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-41034 - ONLYOFFICE DocumentServer Untrusted Pointer Dereference Information Leak and ASLR Bypass

CVE ID :CVE-2026-41034 Published : April 16, 2026, 7:16 a.m. | 6 hours, 41 minutes ago Description :ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026
VulnerabilitàAlta
CVE-2026-41030 - OnlyOffice DesktopEditors Elevation of Privilege

CVE ID :CVE-2026-41030 Published : April 16, 2026, 7:16 a.m. | 6 hours, 41 minutes ago Description :In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE16 apr 2026

Pagina 2236 di 3211

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.