Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

39231 risultati

VulnerabilitàAlta
CVE-2026-35057 - XenForo Stored Cross-Site Scripting via Structured Text Mentions

CVE ID :CVE-2026-35057 Published : April 1, 2026, 1:16 a.m. | 2 hours, 37 minutes ago Description :XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 apr 2026
VulnerabilitàAlta
CVE-2025-71282 (CVSS 7.5)

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.

NVD (NIST)01 apr 2026
VulnerabilitàAlta
CVE-2025-71281 (CVSS 8.8)

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.

NVD (NIST)01 apr 2026
VulnerabilitàCritica
CVE-2025-71279 (CVSS 9.8)

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.

NVD (NIST)01 apr 2026
VulnerabilitàAlta
CVE-2025-71280 - XenForo Local Account Page Caching Information Disclosure

CVE ID :CVE-2025-71280 Published : April 1, 2026, 1:16 a.m. | 2 hours, 37 minutes ago Description :XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 apr 2026
VulnerabilitàAlta
CVE-2026-2394 - Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.

CVE ID :CVE-2026-2394 Published : April 1, 2026, 1:16 a.m. | 2 hours, 37 minutes ago Description :Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 apr 2026
VulnerabilitàAlta
CVE-2025-71279 - XenForo Passkey Security Bypass

CVE ID :CVE-2025-71279 Published : April 1, 2026, 1:16 a.m. | 2 hours, 37 minutes ago Description :XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 apr 2026
VulnerabilitàAlta
CVE-2025-71278 - XenForo OAuth2 Unauthorized Scope Request

CVE ID :CVE-2025-71278 Published : April 1, 2026, 1:16 a.m. | 2 hours, 37 minutes ago Description :XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 apr 2026
VulnerabilitàAlta
CVE-2025-71278 (CVSS 8.8)

XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level.

NVD (NIST)01 apr 2026
VulnerabilitàAlta
CVE-2025-71282 - XenForo Path Disclosure via open_basedir Exceptions

CVE ID :CVE-2025-71282 Published : April 1, 2026, 1:16 a.m. | 2 hours, 37 minutes ago Description :XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 apr 2026
VulnerabilitàAlta
CVE-2025-71281 - XenForo Template Method Call Restriction Bypass

CVE ID :CVE-2025-71281 Published : April 1, 2026, 1:16 a.m. | 2 hours, 37 minutes ago Description :XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE01 apr 2026
VulnerabilitàAlta
CVE-2025-13855 (CVSS 7.6)

IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

NVD (NIST)01 apr 2026

Pagina 2537 di 3270

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.