Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

13126 risultati

VulnerabilitàAlta
CVE-2026-3239 - Strong Testimonials <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via testimonial_view Shortcode

CVE ID :CVE-2026-3239 Published : April 8, 2026, 5:16 a.m. | 40 minutes ago Description :The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 apr 2026
VulnerabilitàAlta
CVE-2026-27787 - MATCHA SNS Cross-Site Scripting (XSS) Vulnerability

CVE ID :CVE-2026-27787 Published : April 8, 2026, 6:16 a.m. | 1 hour, 39 minutes ago Description :Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 apr 2026
VulnerabilitàAlta
CVE-2026-33273 - Matcha Invoice File Upload Code Execution Vulnerability

CVE ID :CVE-2026-33273 Published : April 8, 2026, 6:16 a.m. | 1 hour, 39 minutes ago Description :Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 apr 2026
VulnerabilitàAlta
CVE-2026-24913 - Matcha Invoice SQL Injection Vulnerability

CVE ID :CVE-2026-24913 Published : April 8, 2026, 6:16 a.m. | 1 hour, 39 minutes ago Description :SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 apr 2026
News
OpenSSL 3.6.2 lands with eight CVE fixes

OpenSSL 3.6.2 lands with eight CVE fixes OpenSSL 3.6.2 patches eight CVEs across a range of components. The project rates the most severe issue in the release as Moderate. What got fixed The release fixes incorrect failure handling in RSA KE ... Read more Published Date: Apr 08, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-31790 CVE-2026-31789 CVE-2026-28390 CVE-2026-28389 CVE-2026-28388 CVE-2026-28387 CVE-2026-28386 CVE-2026-2673

CVEfeed Newsroom08 apr 2026
News
Anthropic’s new AI model finds and exploits zero-days across every major OS and browser

Anthropic’s new AI model finds and exploits zero-days across every major OS and browser Automated vulnerability discovery tools have existed for decades, and the gap between finding a bug and building a working exploit has always slowed attackers. That gap is now substantially narrower. ... Read more Published Date: Apr 08, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-4747

CVEfeed Newsroom08 apr 2026
News
Claude Uncovers 13-Year-Old RCE Flaw in Apache ActiveMQ in Just 10 Minutes

Claude Uncovers 13-Year-Old RCE Flaw in Apache ActiveMQ in Just 10 Minutes A critical remote code execution (RCE) vulnerability has been disclosed in Apache ActiveMQ Classic, a flaw that sat undetected for over a decade and was ultimately discovered not by a human researcher ... Read more Published Date: Apr 08, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197 CVE-2024-32114 CVE-2022-41678 CVE-2023-46604 CVE-2016-3088

CVEfeed Newsroom08 apr 2026
News
CUPS Vulnerability Chain Enables Remote Attacker to Execute Malicious Code as Root User

CUPS Vulnerability Chain Enables Remote Attacker to Execute Malicious Code as Root User A critical vulnerability chain in the Common Unix Printing System (CUPS) that allows unauthenticated remote attackers to execute arbitrary malicious code with root system privileges. Security research ... Read more Published Date: Apr 08, 2026 (23 hours, 3 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34990 CVE-2026-34980

CVEfeed Newsroom08 apr 2026
News
OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed

OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed OpenSSL has released a comprehensive security advisory detailing seven vulnerabilities ranging from Moderate to Low severity. The report, dated April 7, 2026, highlights critical fixes for modern vers ... Read more Published Date: Apr 08, 2026 (23 hours, 14 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-31790 CVE-2026-31789 CVE-2026-28390 CVE-2026-28389 CVE-2026-28388 CVE-2026-28387 CVE-2026-28386 CVE-2026-34950 CVE-2026-35616 CVE-2026-5281 CVE-2026-3502 CVE-2026-33032 CVE-2025-15467 CVE-2026-21962 CVE-2022-2274

CVEfeed Newsroom08 apr 2026
VulnerabilitàAlta
CVE-2026-1163 - Insufficient Session Expiration in parisneo/lollms

CVE ID :CVE-2026-1163 Published : April 8, 2026, 3:16 a.m. | 2 hours, 40 minutes ago Description :An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of logic to reject requests after a period of inactivity and the excessively long default session duration of 31 days. The vulnerability enables an attacker to maintain persistent access to a compromised account, even after the victim resets their password. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 apr 2026
VulnerabilitàAlta
CVE-2026-5726 - ASDA-Soft Stack-based Buffer Overflow Vulnerability

CVE ID :CVE-2026-5726 Published : April 8, 2026, 3:16 a.m. | 2 hours, 40 minutes ago Description :ASDA-Soft Stack-based Buffer Overflow Vulnerability Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 apr 2026
VulnerabilitàAlta
CVE-2026-2988 - Blubrry PowerPress <= 11.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via powerpress and podcast Shortcodes

CVE ID :CVE-2026-2988 Published : April 8, 2026, 4:17 a.m. | 1 hour, 39 minutes ago Description :The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 apr 2026

Pagina 252 di 1094

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.