Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38738 risultati

VulnerabilitàCritica
CVE-2026-1830 (CVSS 9.8)

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve the sync code, upload PHP files with path traversal, and achieve remote code execution on the server.

NVD (NIST)09 apr 2026
VulnerabilitàAlta
CVE-2026-1830 - Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload

CVE ID :CVE-2026-1830 Published : April 9, 2026, 5:16 a.m. | 4 hours, 40 minutes ago Description :The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve the sync code, upload PHP files with path traversal, and achieve remote code execution on the server. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2026-5848 - jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection

CVE ID :CVE-2026-5848 Published : April 9, 2026, 6:16 a.m. | 7 hours, 40 minutes ago Description :A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getConnection of the file /drag/onlDragDataSource/testConnection of the component Data Source Handler. Performing a manipulation of the argument dbUrl results in code injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor confirmed the issue and will provide a fix in the upcoming release. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2026-5837 (CVSS 7.3)

A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.php. The manipulation of the argument Comment results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

NVD (NIST)09 apr 2026
VulnerabilitàAlta
CVE-2026-5837 - PHPGurukul News Portal Project news-details.php sql injection

CVE ID :CVE-2026-5837 Published : April 9, 2026, 4:17 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.php. The manipulation of the argument Comment results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
News
Palo Alto Networks Patches Trio of Security Flaws: From Agent Disabling to System Privileges

Palo Alto Networks Patches Trio of Security Flaws: From Agent Disabling to System Privileges Palo Alto Networks has released critical updates to address three distinct vulnerabilities across its security ecosystem. The flaws impact the Cortex XDR Agent, the Autonomous Digital Experience Manag ... Read more Published Date: Apr 09, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 apr 2026
VulnerabilitàAlta
CVE-2026-5836 - code-projects Online Shoe Store admin_product.php cross site scripting

CVE ID :CVE-2026-5836 Published : April 9, 2026, 4:17 a.m. | 5 hours, 39 minutes ago Description :A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument product_name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
News
Security Alert: GitLab Issues Patch for High-Severity Vulnerabilities Across CE and EE

Security Alert: GitLab Issues Patch for High-Severity Vulnerabilities Across CE and EE GitLab has released critical security updates for Community Edition (CE) and Enterprise Edition (EE). Versions 18.10.3, 18.9.5, and 18.8.9 address multiple high and medium-severity flaws that could co ... Read more Published Date: Apr 09, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-5173 CVE-2026-4916 CVE-2026-2104 CVE-2026-1752 CVE-2026-1516 CVE-2026-1092 CVE-2025-12664 CVE-2026-22679 CVE-2026-35616 CVE-2026-5281 CVE-2026-3502 CVE-2026-1340

CVEfeed Newsroom09 apr 2026
VulnerabilitàAlta
CVE-2026-5835 - code-projects Online Shoe Store admin_football.php cross site scripting

CVE ID :CVE-2026-5835 Published : April 9, 2026, 4:17 a.m. | 5 hours, 39 minutes ago Description :A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a manipulation of the argument product_name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
News
SonicWall Issues Critical Patch for SMA 1000 Series to Stop SQL Injection and MFA Bypasses

SonicWall Issues Critical Patch for SMA 1000 Series to Stop SQL Injection and MFA Bypasses SonicWall has released a series of patches for its SMA 1000 series appliances to address four distinct vulnerabilities. The flaws range from a high-severity SQL injection that allows privilege escalat ... Read more Published Date: Apr 09, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 apr 2026
VulnerabilitàAlta
CVE-2026-5834 - code-projects Online Shoe Store admin_running.php cross site scripting

CVE ID :CVE-2026-5834 Published : April 9, 2026, 4:17 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2026-3574 - Experto Dashboard for WooCommerce <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Navigation Font Size' Setting

CVE ID :CVE-2026-3574 Published : April 9, 2026, 4:17 a.m. | 1 hour, 39 minutes ago Description :The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Size', 'Navigation Font Weight', 'Heading Font Size', 'Heading Font Weight', 'Text Font Size', and 'Text Font Weight') in all versions up to and including 1.0.4. This is due to insufficient input sanitization (no sanitize callback in register_setting()) and missing output escaping (no esc_attr() in the field_callback() printf output) on user-supplied values. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in the plugin settings page that will execute whenever a user accesses the settings page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026

Pagina 2365 di 3229

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.