Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

39463 risultati

VulnerabilitàAlta
CVE-2026-22742 - Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching

CVE ID :CVE-2026-22742 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended internal or external destinations. This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-22743 - Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore

CVE ID :CVE-2026-22743 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() embeds the key into a backtick-delimited Cypher property accessor (node.`metadata.`) after stripping only double quotes, without escaping embedded backticks.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2024-14028 - Multiple implicit reads in parallel can result in a crash or denial of service

CVE ID :CVE-2024-14028 Published : March 27, 2026, 6:16 a.m. | 3 hours, 36 minutes ago Description :Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.31 smartLink HW-PN: before 1.02. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-22738 - SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution

CVE ID :CVE-2026-22738 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key are affected. This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-33559 - WordPress Plugin "OpenStreetMap" Cross-Site Scripting (XSS)

CVE ID :CVE-2026-33559 Published : March 27, 2026, 6:16 a.m. | 5 hours, 36 minutes ago Description :WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim user accesses this page, the script may be executed in the user's web browser. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-34353 - OCaml Bigarray Integer Overflow Arbitrary Memory Reading Vulnerability

CVE ID :CVE-2026-34353 Published : March 27, 2026, 6:16 a.m. | 7 hours, 36 minutes ago Description :In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-4910 (CVSS 7.3)

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus bis 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of the component Endpoint. Such manipulation of the argument State leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)27 mar 2026
VulnerabilitàAlta
CVE-2026-4910 - Shenzhen Ruiming Technology Streamax Crocus Endpoint RemoteFormat.do sql injection

CVE ID :CVE-2026-4910 Published : March 27, 2026, 4:16 a.m. | 3 hours, 37 minutes ago Description :A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus bis 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of the component Endpoint. Such manipulation of the argument State leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-3098 - Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll

CVE ID :CVE-2026-3098 Published : March 27, 2026, 4:16 a.m. | 3 hours, 37 minutes ago Description :The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-4909 - code-projects Exam Form Submission update_s7.php cross site scripting

CVE ID :CVE-2026-4909 Published : March 27, 2026, 3:16 a.m. | 4 hours, 37 minutes ago Description :A weakness has been identified in code-projects Exam Form Submission 1.0/7.php. This impacts an unknown function of the file /admin/update_s7.php. This manipulation of the argument sname causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026
VulnerabilitàAlta
CVE-2026-4908 (CVSS 7.3)

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

NVD (NIST)27 mar 2026
VulnerabilitàAlta
CVE-2026-4908 - code-projects Simple Laundry System Parameter modstaffinfo.php sql injection

CVE ID :CVE-2026-4908 Published : March 27, 2026, 3:16 a.m. | 4 hours, 37 minutes ago Description :A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mar 2026

Pagina 2620 di 3289

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.