Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45477 risultati

VulnerabilitàAlta
CVE-2026-96271 (CVSS 7.1)

Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-95925 (CVSS 7.3)

A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-95924 (CVSS 7.3)

A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-95925 - SourceCodester Online Reviewer Management System btn_functions.php update sql injection

CVE ID :CVE-2026-95925 Published : Sept. 23, 2026, 1:16 a.m. | 3 hours, 11 minutes ago Description :A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96273 - Ghidra before 12.1.4 Denial of Service via Crafted Database

CVE ID :CVE-2026-96273 Published : Sept. 23, 2026, 1:16 a.m. | 3 hours, 11 minutes ago Description :Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious program database file that, when imported, causes the application to stall and prevents resource cleanup or graceful shutdown. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96272 - ClipBucket v5 before 5.5.3-#182 SQL Injection via search_result.php

CVE ID :CVE-2026-96272 Published : Sept. 23, 2026, 1:16 a.m. | 3 hours, 11 minutes ago Description :ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96271 - Photoview through 2.4.0 Authorization Bypass via shareAlbum

CVE ID :CVE-2026-96271 Published : Sept. 23, 2026, 1:16 a.m. | 3 hours, 11 minutes ago Description :Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-95924 - SourceCodester Online Reviewer Management System btn_functions.php add sql injection

CVE ID :CVE-2026-95924 Published : Sept. 23, 2026, 1:16 a.m. | 3 hours, 11 minutes ago Description :A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-95897 - Dask Loader core.py from_npy_stack deserialization

CVE ID :CVE-2026-95897 Published : Sept. 23, 2026, 1:16 a.m. | 3 hours, 11 minutes ago Description :A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
News
CISA adds Five Vulnerabilities to Exploitable Catalog

CISA adds Five Vulnerabilities to Exploitable Catalog CISA’s Known Exploited Vulnerabilities (KEV) Catalog continues to highlight a familiar pattern: vulnerabilities affecting network infrastructure, security appliances and management platforms are beco ... Read more Published Date: Sep 23, 2026 (3 days, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-93616 CVE-2026-85102 CVE-2026-16812 CVE-2026-7273 CVE-2026-9501

CVEfeed Newsroom23 set 2026
VulnerabilitàAlta
CVE-2026-95868 - AdithyaYelloju Restaurant-Management-System Search Form display_menu.php mysqli_query sql injection

CVE ID :CVE-2026-95868 Published : Sept. 23, 2026, 12:17 a.m. | 4 hours, 10 minutes ago Description :A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqli_query of the file admin/display_menu.php of the component Search Form. This manipulation of the argument s1 causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-95833 - itsourcecode Leave Management System index.php sql injection

CVE ID :CVE-2026-95833 Published : Sept. 23, 2026, 12:17 a.m. | 4 hours, 10 minutes ago Description :A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 225 di 3790

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.