Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

39765 risultati

News
Critical RCE Flaw in PTC Windchill and FlexPLM Puts Product Data at Risk

Critical RCE Flaw in PTC Windchill and FlexPLM Puts Product Data at Risk PTC has issued a high-priority security advisory regarding a critical vulnerability affecting its Windchill and FlexPLM product lifecycle management suites. The flaw, tracked as CVE-2026-4681 (CVSS 10 ... Read more Published Date: Mar 26, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-3608 CVE-2026-4681 CVE-2025-29969

CVEfeed Newsroom26 mar 2026
VulnerabilitàAlta
CVE-2018-25210 (CVSS 8.2)

WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL payloads through the 'urun' parameter to execute boolean-based blind, error-based, time-based blind, and stacked query attacks against the backend database.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25209 (CVSS 8.2)

OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries through the username parameter. Attackers can submit POST requests to /bin/controller.php with malicious SQL code in the username field to extract sensitive database information or bypass authentication.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25208 (CVSS 8.2)

qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through filter_by parameters. Attackers can submit malicious POST requests to the timeReport endpoint with crafted filter_by[CommentCreatedFrom] and filter_by[CommentCreatedTo] parameters to execute arbitrary SQL queries and retrieve sensitive data.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25207 (CVSS 7.1)

Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-system.php or add-category.php with crafted SQL payloads in POST parameters to extract sensitive database information or bypass authentication.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25206 (CVSS 8.2)

KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_item_search' parameter in edit.php. Attackers can submit POST requests with malicious SQL payloads to extract sensitive database information using boolean-based blind or error-based injection techniques.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25205 (CVSS 8.2)

ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Attackers can submit malicious SQL payloads via GET or POST requests to the /search endpoint to extract sensitive database information using boolean-based blind or error-based techniques.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25204 (CVSS 8.2)

Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can send POST requests to the admin login endpoint with boolean-based blind SQL injection payloads in the username field to manipulate database queries and gain unauthorized access.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25203 (CVSS 8.2)

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind or time-based blind SQL injection payloads in the email field to extract sensitive database information.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25202 (CVSS 8.2)

SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id' parameter in the signIn endpoint. Attackers can submit POST requests with boolean-based blind, stacked queries, or time-based blind SQL injection payloads to extract sensitive data or compromise the application.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25201 (CVSS 7.1)

School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious payloads using boolean-based blind SQL injection techniques to the processlogin endpoint to authenticate as administrator without valid credentials.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25195 (CVSS 8.2)

Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.

NVD (NIST)26 mar 2026

Pagina 2662 di 3314

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.