Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38653 risultati

VulnerabilitàAlta
CVE-2025-14545 - YML for Yandex Market < 5.0.26 - Shop Manager+ RCE via Feed Generation

CVE ID :CVE-2025-14545 Published : April 10, 2026, 7:16 a.m. | 40 minutes ago Description :The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation process. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6032 - code-projects Simple Laundry System checkcheckout.php cross site scripting

CVE ID :CVE-2026-6032 Published : April 10, 2026, 8:16 a.m. | 3 hours, 40 minutes ago Description :A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkcheckout.php. Performing a manipulation of the argument serviceId results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6031 - code-projects Simple IT Discussion Forum add-category-function.php sql injection

CVE ID :CVE-2026-6031 Published : April 10, 2026, 8:16 a.m. | 3 hours, 40 minutes ago Description :A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the file /add-category-function.php. Such manipulation of the argument Category leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
News
GitLab Security Update Fixes High-Severity CVE-2026-5173, 11 Other Flaws

GitLab Security Update Fixes High-Severity CVE-2026-5173, 11 Other Flaws GitLab has rolled out a major security update to address a series of vulnerabilities impacting both its Community Edition (CE) and Enterprise Edition (EE) platforms. The GitLab security update resolve ... Read more Published Date: Apr 10, 2026 (3 days, 2 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom10 apr 2026
News
AWS Patches Critical RCE and Escalate Privileges in Research and Engineering Studio

AWS Patches Critical RCE and Escalate Privileges in Research and Engineering Studio Amazon Web Services (AWS) has released an important security bulletin addressing three severe vulnerabilities in its Research and Engineering Studio (RES). These flaws could allow authenticated attack ... Read more Published Date: Apr 10, 2026 (3 days, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5709 CVE-2026-5708 CVE-2026-5707

CVEfeed Newsroom10 apr 2026
VulnerabilitàCritica
CVE-2026-6025 (CVSS 9.8)

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

NVD (NIST)10 apr 2026
VulnerabilitàAlta
CVE-2026-6024 (CVSS 7.3)

A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

NVD (NIST)10 apr 2026
VulnerabilitàAlta
CVE-2026-6016 (CVSS 8.8)

A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.

NVD (NIST)10 apr 2026
VulnerabilitàAlta
CVE-2026-6015 (CVSS 8.8)

A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

NVD (NIST)10 apr 2026
VulnerabilitàAlta
CVE-2026-6025 - Totolink A7100RU CGI cstecgi.cgi setSyslogCfg os command injection

CVE ID :CVE-2026-6025 Published : April 10, 2026, 5:30 a.m. | 26 minutes ago Description :A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 apr 2026
VulnerabilitàAlta
CVE-2026-6014 (CVSS 8.8)

A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. This manipulation of the argument webpage causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

NVD (NIST)10 apr 2026
VulnerabilitàAlta
CVE-2026-6013 (CVSS 8.8)

A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

NVD (NIST)10 apr 2026

Pagina 2335 di 3222

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.