Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38642 risultati

VulnerabilitàAlta
CVE-2026-40226 - systemd nspawn Escape-to-Host Vulnerability

CVE ID :CVE-2026-40226 Published : April 10, 2026, 3:18 p.m. | 38 minutes ago Description :In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-36236 - SourceCodester Engineers Online Portal SQL Injection

CVE ID :CVE-2026-36236 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-36235 - iSourcecode Online Student Enrollment System SQL Injection

CVE ID :CVE-2026-36235 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-36233 - iSourcecode Online Student Enrollment System SQL Injection

CVE ID :CVE-2026-36233 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for appropriate cleaning or validation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-36234 - Itsourcecode Online Student Enrollment System SQL Injection Vulnerability

CVE ID :CVE-2026-36234 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-36232 - iSourcecode Online Student Enrollment System SQL Injection

CVE ID :CVE-2026-36232 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or validation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-29861 - MySQL PHP Login System SQL Injection

CVE ID :CVE-2026-29861 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-23782 - BMC Control-M/MFT API Secret Disclosure Vulnerability

CVE ID :CVE-2026-23782 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unauthorized access. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-31262 - Altenar Sportsbook Software Platform SB2 Cross Site Scripting (XSS)

CVE ID :CVE-2026-31262 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the URL parameter Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-23780 - BMC Control-M SQL Injection Vulnerability

CVE ID :CVE-2026-23780 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write operations and potentially lead to remote code execution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2025-44560 - Owntone-Server Buffer Overflow Vulnerability

CVE ID :CVE-2025-44560 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-40225 - "Systemd Udev Kernel Output Execution Vulnerability"

CVE ID :CVE-2026-40225 Published : April 10, 2026, 3:16 p.m. | 40 minutes ago Description :In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026

Pagina 2328 di 3221

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.