Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38603 risultati

VulnerabilitàAlta
CVE-2019-25707 (CVSS 7.1)

eBrigade ERP 4.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to pdf.php with crafted SQL payloads in the 'id' parameter to extract sensitive database information including table names and schema details.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2019-25706 (CVSS 7.5)

Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2019-25705 (CVSS 8.4)

Echo Mirage 3.1 contains a stack buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized string in the Rules action field. Attackers can create a malicious text file with a crafted payload exceeding buffer boundaries and paste it into the action field through the Rules dialog to trigger the overflow and overwrite the return address.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2019-25703 (CVSS 7.1)

ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values containing SQL commands to extract sensitive database information.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2019-25706 - Across DR-810 ROM-0 Unauthenticated File Disclosure

CVE ID :CVE-2019-25706 Published : April 12, 2026, 1:16 p.m. | 10 hours, 40 minutes ago Description :Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoint without authentication to retrieve and decompress the backup file, exposing router passwords and other sensitive configuration data. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2019-25707 - eBrigade ERP 4.5 SQL Injection via pdf.php

CVE ID :CVE-2019-25707 Published : April 12, 2026, 1:16 p.m. | 10 hours, 40 minutes ago Description :eBrigade ERP 4.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to pdf.php with crafted SQL payloads in the 'id' parameter to extract sensitive database information including table names and schema details. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2019-25709 - CF Image Hosting Script 1.6.5 Unauthorized Database Access

CVE ID :CVE-2019-25709 Published : April 12, 2026, 1:16 p.m. | 10 hours, 40 minutes ago Description :CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2019-25703 - ImpressCMS 1.3.11 SQL Injection via bid Parameter

CVE ID :CVE-2019-25703 Published : April 12, 2026, 1:16 p.m. | 10 hours, 40 minutes ago Description :ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values containing SQL commands to extract sensitive database information. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2019-25705 - Echo Mirage 3.1 Stack Buffer Overflow via Rules Action Field

CVE ID :CVE-2019-25705 Published : April 12, 2026, 1:16 p.m. | 10 hours, 40 minutes ago Description :Echo Mirage 3.1 contains a stack buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized string in the Rules action field. Attackers can create a malicious text file with a crafted payload exceeding buffer boundaries and paste it into the action field through the Rules dialog to trigger the overflow and overwrite the return address. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2019-25708 - Heatmiser Wifi Thermostat 1.7 Cross-Site Request Forgery

CVE ID :CVE-2019-25708 Published : April 12, 2026, 1:16 p.m. | 10 hours, 40 minutes ago Description :Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm, usps, and cfps to modify the admin username and password without user consent. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE12 apr 2026
VulnerabilitàAlta
CVE-2019-25701 (CVSS 8.4)

Easy Video to iPod Converter 1.6.20 contains a local buffer overflow vulnerability in the user registration field that allows local attackers to overwrite the structured exception handler. Attackers can input a crafted payload exceeding 996 bytes in the username field to trigger SEH overwrite and execute arbitrary code with user privileges.

NVD (NIST)12 apr 2026
VulnerabilitàAlta
CVE-2019-25699 (CVSS 7.1)

Newsbull Haber Script 1.0.0 contains multiple SQL injection vulnerabilities in the search parameter that allow authenticated attackers to extract database information through time-based, blind, and boolean-based injection techniques. Attackers can inject malicious SQL code through the search parameter in endpoints like /admin/comment/records, /admin/category/records, /admin/news/records, and /admin/menu/childs to manipulate database queries and retrieve sensitive data.

NVD (NIST)12 apr 2026

Pagina 2310 di 3217

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.