Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38911 risultati

VulnerabilitàAlta
CVE-2026-5467 - Casdoor OAuth Authorization Request redirect

CVE ID :CVE-2026-5467 Published : April 3, 2026, 12:16 p.m. | 1 hour, 38 minutes ago Description :A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open redirect. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-4107 - Stored XSS Vulnerability

CVE ID :CVE-2026-4107 Published : April 3, 2026, 12:16 p.m. | 1 hour, 38 minutes ago Description :Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-4108 - Stored XSS Vulnerability

CVE ID :CVE-2026-4108 Published : April 3, 2026, 12:16 p.m. | 1 hour, 38 minutes ago Description :Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-3880 - Stored XSS Vulnerability

CVE ID :CVE-2026-3880 Published : April 3, 2026, 12:16 p.m. | 1 hour, 38 minutes ago Description :Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-3879 - Stored XSS Vulnerability

CVE ID :CVE-2026-3879 Published : April 3, 2026, 12:16 p.m. | 1 hour, 38 minutes ago Description :Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-28703 - Stored XSS Vulnerability

CVE ID :CVE-2026-28703 Published : April 3, 2026, 12:16 p.m. | 1 hour, 38 minutes ago Description :Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
News
Progress ShareFile-servers via kritieke kwetsbaarheid volledig over te nemen

Progress ShareFile-servers via kritieke kwetsbaarheid volledig over te nemen Onderzoekers waarschuwen voor twee kwetsbaarheden in Progress ShareFile die het voor ongeauthenticeerde aanvallers mogelijk maken om kwetsbare servers over te nemen. Progress werd begin februari door ... Read more Published Date: Apr 03, 2026 (2 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-2701 CVE-2026-2699

CVEfeed Newsroom03 apr 2026
News
The MuPDF Vulnerability Turning “Safe” PDFs into System Hijackers

The MuPDF Vulnerability Turning “Safe” PDFs into System Hijackers A significant security flaw has been unearthed in Artifex MuPDF, a popular framework prized for its speed and versatility in handling PDFs, XPS, and e-books. Labeled as CVE-2026-3308, this integer ove ... Read more Published Date: Apr 03, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20160 CVE-2026-35093 CVE-2026-5281 CVE-2026-3308 CVE-2026-3502 CVE-2026-33032 CVE-2026-33179 CVE-2026-33150 CVE-2026-21962

CVEfeed Newsroom03 apr 2026
VulnerabilitàAlta
CVE-2026-28754 - Stored XSS Vulnerability

CVE ID :CVE-2026-28754 Published : April 3, 2026, 11:17 a.m. | 2 hours, 37 minutes ago Description :Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
VulnerabilitàAlta
CVE-2026-28756 - Stored XSS Vulnerability

CVE ID :CVE-2026-28756 Published : April 3, 2026, 11:17 a.m. | 2 hours, 37 minutes ago Description :Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE03 apr 2026
News
Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers

Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers Multiple high-severity vulnerabilities exist in TP-Link’s Tapo C520WS smart security cameras. If exploited, these vulnerabilities may allow adjacent attackers to trigger Denial-of-Service (DoS) condit ... Read more Published Date: Apr 03, 2026 (2 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34124 CVE-2026-34122 CVE-2026-34121 CVE-2026-34120 CVE-2026-34119 CVE-2026-34118

CVEfeed Newsroom03 apr 2026
VulnerabilitàAlta
CVE-2026-4350 (CVSS 8.1)

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verification. The unsanitized filename is concatenated with the storage directory path and passed to `unlink()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server by using `../` path traversal sequences, including `wp-config.php` which would force WordPress into the installation wizard and allow full site takeover.

NVD (NIST)03 apr 2026

Pagina 2470 di 3243

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.