News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38581 risultati
Critical 9.8 RCE Flaw in Qlik Talend Threatens Enterprise Data Pipelines QlikTech has issued an urgent security advisory regarding a critical vulnerability in Talend JobServer and Talend Runtime that could allow unauthenticated attackers to seize total control of affected ... Read more Published Date: Apr 14, 2026 (16 hours, 38 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-6264 CVE-2026-22679 CVE-2026-35616 CVE-2026-27728 CVE-2023-48365
NCSC verwacht grootschalig misbruik van kritiek Adobe Acrobat-lek Het Nationaal Cyber Security Centrum (NCSC) verwacht op korte termijn grootschalig misbruik van een kritieke kwetsbaarheid in Adobe Acrobat, nu proof-of-concept exploitcode op internet is verschenen. ... Read more Published Date: Apr 14, 2026 (16 hours, 51 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34621
Hackers Exploit Kali Forms Vulnerability to Take Over WordPress Sites A recently disclosed Kali Forms vulnerability affecting a widely used WordPress plugin has escalated into an active security threat, enabling unauthenticated attackers to achieve Remote Code Execution ... Read more Published Date: Apr 14, 2026 (17 hours, 4 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34621 CVE-2026-4681 CVE-2026-1490 CVE-2026-21858
Hijacking the Soundboard: Critical 9.8 RCE Flaws Hit Ubiquiti UniFi Play Audio Ubiquiti has issued an urgent security advisory for its UniFi Play audio lineup, addressing a suite of vulnerabilities that could allow attackers to seize total control of network-connected amplifiers ... Read more Published Date: Apr 14, 2026 (13 hours, 25 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-22566 CVE-2026-22565 CVE-2026-22564 CVE-2026-22563 CVE-2026-22562 CVE-2026-22679 CVE-2021-4473 CVE-2026-35616 CVE-2026-5281 CVE-2026-22557
CVE ID :CVE-2026-2582 Published : April 14, 2026, 7:16 a.m. | 6 hours, 41 minutes ago Description :The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical 9.9 Alert: SAP’s April 2026 Patch Day Targets Major SQL Injection SAP has marked its latest monthly security update with the release of 19 new security notes and one update to a previously issued advisory. This month’s “Patch Day” is highlighted by a critical severi ... Read more Published Date: Apr 14, 2026 (9 hours, 53 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34264 CVE-2026-34262 CVE-2026-34256 CVE-2026-27683 CVE-2026-27681 CVE-2026-27675 CVE-2026-27674 CVE-2026-0512 CVE-2026-22679 CVE-2026-35616 CVE-2026-5281 CVE-2025-64775 CVE-2025-42944
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The vulnerability in question is ... Read more Published Date: Apr 14, 2026 (11 hours, 6 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2025-55182 CVE-2025-0520
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added half a dozen security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitatio ... Read more Published Date: Apr 14, 2026 (11 hours, 17 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2026-21643 CVE-2025-55182 CVE-2025-60710 CVE-2023-36424 CVE-2023-21529 CVE-2020-9715 CVE-2012-1854
CVE ID :CVE-2026-3017 Published : April 14, 2026, 6:16 a.m. | 7 hours, 41 minutes ago Description :The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4059 Published : April 14, 2026, 4:17 a.m. | 9 hours, 40 minutes ago Description :The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute in all versions up to, and including, 3.3.5. This is due to insufficient input sanitization and missing output escaping on user-supplied shortcode attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4479 Published : April 14, 2026, 4:17 a.m. | 9 hours, 40 minutes ago Description :The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2281 di 3216