Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45489 risultati

VulnerabilitàAlta
CVE-2026-88416 - MCMS SQL Injection Vulnerability

CVE ID :CVE-2026-88416 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-88418 - CMSimple Cross-Site Request Forgery to Remote Code Execution

CVE ID :CVE-2026-88418 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker can induce a logged-in administrator's browser to issue a forged content-save request with a text payload containing a scripting marker. The marker is stored verbatim into content/content.php; on every subsequent page view evaluate_cmsimple_scripting() (functions.php) executes the marker body with PHP eval() — for all visitors, including unauthenticated ones. This yields persistent remote code execution on the web server. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-83801 - Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text

CVE ID :CVE-2026-83801 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, and a user with dcim.add_modulefamily or dcim.change_modulefamily permission can store it in a Module Family name. Nautobot assigns these values to form field help_text rendered by render_field.html through Django's |safe filter without adequate neutralization. The stored content executes in the authenticated browser session of any user, including an administrator or superuser, who opens an affected create or edit form. This can enable actions as the victim, session or token theft, and further privilege escalation. This issue is fixed in versions 2.4.37 and 3.1.8. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-83805 - Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs

CVE ID :CVE-2026-83805 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under review, or the one-response-per-user restriction applied by the intended approve and deny actions. A user with only extras.add_approvalworkflowstageresponse can submit approved responses directly, while writable user and state fields permit responses to be attributed to arbitrary users. These forged responses can satisfy min_approvers, approve the workflow, and activate its gated ScheduledJob without a legitimate approver. This issue is fixed in version 3.1.8. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-87121 - Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application

CVE ID :CVE-2026-87121 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-79767 - Gardener: Authorization Bypass via Group Subject Injection

CVE ID :CVE-2026-79767 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check compares changes to User subjects but does not account for Group or ServiceAccount subjects in Project.spec.members. A project administrator who lacks manage-members permission can add arbitrary Group or ServiceAccount subjects, including the system:authenticated Group, and thereby grant broad project access. The resulting access can include Shoots, Secrets, and cloud provider credentials. This issue is fixed in versions 1.142.6, 1.143.3, 1.144.2, and 1.145.0. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-77322 - SIPGO: DoS via unvalidated WebSocket frame length

CVE ID :CVE-2026-77322 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An unauthenticated WS or WSS peer can send a frame header declaring an extremely large payload, causing an oversized allocation or a makeslice length panic before the payload is read and crashing or exhausting memory in the server process. This issue is fixed in version 1.4.3. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-76713 - Authenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)

CVE ID :CVE-2026-76713 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-76712 - Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)

CVE ID :CVE-2026-76712 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security controls, or a denial of service condition on the affected system. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-76714 - Authenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)

CVE ID :CVE-2026-76714 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-76715 - Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)

CVE ID :CVE-2026-76715 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026
VulnerabilitàAlta
CVE-2026-76716 - Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)

CVE ID :CVE-2026-76716 Published : Sept. 22, 2026, 8:17 p.m. | 13 minutes ago Description :Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could result in a denial of service condition or unauthorized access to sensitive information. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 set 2026

Pagina 233 di 3791

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.