Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38866 risultati

VulnerabilitàAlta
CVE-2026-5552 - PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection

CVE ID :CVE-2026-5552 Published : April 5, 2026, 9:16 a.m. | 4 hours, 39 minutes ago Description :A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5551 (CVSS 7.3)

A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.php of the component Parameter Handler. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2026-5551 - itsourcecode Free Hotel Reservation System Parameter login.php sql injection

CVE ID :CVE-2026-5551 Published : April 5, 2026, 9:16 a.m. | 4 hours, 39 minutes ago Description :A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/login.php of the component Parameter Handler. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5555 - code-projects Concert Ticket Reservation System Parameter login.php sql injection

CVE ID :CVE-2026-5555 Published : April 5, 2026, 10:16 a.m. | 5 hours, 39 minutes ago Description :A weakness has been identified in code-projects Concert Ticket Reservation System 1.0. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5554 - code-projects Concert Ticket Reservation System Parameter process_search.php sql injection

CVE ID :CVE-2026-5554 Published : April 5, 2026, 10:16 a.m. | 5 hours, 39 minutes ago Description :A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5550 (CVSS 8.8)

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2026-5550 - Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

CVE ID :CVE-2026-5550 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5548 (CVSS 8.8)

A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2026-5549 - Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key

CVE ID :CVE-2026-5549 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5548 - Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

CVE ID :CVE-2026-5548 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
News
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited

Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Financial groups lay out a plan to fight AI identity attacks Generative AI tools have brought the cost ... Read more Published Date: Apr 05, 2026 (2 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616 CVE-2026-20093 CVE-2026-5281 CVE-2026-3502 CVE-2026-21643

CVEfeed Newsroom05 apr 2026
VulnerabilitàAlta
CVE-2026-5546 - Campcodes Complete Online Learning Management System Crud_model.php add_lesson unrestricted upload

CVE ID :CVE-2026-5546 Published : April 5, 2026, 7:16 a.m. | 4 hours, 39 minutes ago Description :A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026

Pagina 2445 di 3239

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.