Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

39344 risultati

VulnerabilitàAlta
CVE-2026-30561 - SourceCodester Sales and Inventory System Reflected Cross-Site Scripting (XSS)

CVE ID :CVE-2026-30561 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_purchase.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-30562 - SourceCodester Sales and Inventory System Reflected Cross-Site Scripting (XSS)

CVE ID :CVE-2026-30562 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-30556 - SourceCodester Sales and Inventory System Reflected Cross-Site Scripting (XSS)

CVE ID :CVE-2026-30556 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the index.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-30558 - SourceCodester Sales and Inventory System Reflected Cross-Site Scripting (XSS)

CVE ID :CVE-2026-30558 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_customer.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-30557 - SourceCodester Sales and Inventory System Reflected Cross-Site Scripting

CVE ID :CVE-2026-30557 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_category.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-30559 - SourceCodester Sales and Inventory System Reflected XSS

CVE ID :CVE-2026-30559 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_sales.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-2285 - CVE-2026-2285

CVE ID :CVE-2026-2285 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-2286 - CVE-2026-2286

CVE ID :CVE-2026-2286 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-2287 - CVE-2026-2287

CVE ID :CVE-2026-2287 Published : March 30, 2026, 4:16 p.m. | 1 hour, 38 minutes ago Description :CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
News
High-Severity RCE Discovered in Foreman’s WebSocket Proxy

High-Severity RCE Discovered in Foreman’s WebSocket Proxy Security researchers have identified a high-severity vulnerability in Foreman, the popular open-source lifecycle management tool used by system administrators to provision and orchestrate thousands of ... Read more Published Date: Mar 30, 2026 (1 day, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-1961 CVE-2026-27728

CVEfeed Newsroom30 mar 2026
VulnerabilitàAlta
CVE-2026-5164 - Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request

CVE ID :CVE-2026-5164 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial of Service (DoS). Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026
VulnerabilitàAlta
CVE-2026-5165 - Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset

CVE ID :CVE-2026-5165 Published : March 30, 2026, 3:16 p.m. | 37 minutes ago Description :A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-free vulnerability. This issue could allow a local attacker to corrupt system memory, potentially leading to system instability or unexpected behavior. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE30 mar 2026

Pagina 2575 di 3279

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.