Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

40130 risultati

VulnerabilitàAlta
CVE-2026-22790 - EVerest's unchecked SLAC payload length causes stack overflow in HomeplugMessage::setup_payload

CVE ID :CVE-2026-22790 Published : March 26, 2026, 3:16 p.m. | 36 minutes ago Description :EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release builds the check is removed, so oversized SLAC payloads are `memcpy`'d into a ~1497-byte stack buffer, corrupting the stack and enabling remote code execution from network-provided frames. Version 2026.02.0 contains a patch. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
News
High-Severity strongSwan Flaw Enables Remote VPN Gateway Crashes

High-Severity strongSwan Flaw Enables Remote VPN Gateway Crashes A high-severity security vulnerability has been uncovered in strongSwan, the widely used open-source IPsec-based VPN solution. The flaw, tracked as CVE-2026-25075 with a CVSSv4 score of 8.7, resides i ... Read more Published Date: Mar 26, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-23921 CVE-2026-25075 CVE-2026-3584 CVE-2026-0229 CVE-2025-29969 CVE-2023-41913

CVEfeed Newsroom26 mar 2026
VulnerabilitàAlta
CVE-2026-4877 - itsourcecode Payroll Management System index.php cross site scripting

CVE ID :CVE-2026-4877 Published : March 26, 2026, 2:16 p.m. | 1 hour, 36 minutes ago Description :A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-4876 - itsourcecode Free Hotel Reservation System index.php sql injection

CVE ID :CVE-2026-4876 Published : March 26, 2026, 2:16 p.m. | 1 hour, 36 minutes ago Description :A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_amenities/index.php?view=editpic. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-2511 (CVSS 7.5)

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()` without enclosing the result in quotes in the SQL query, rendering the escaping ineffective against payloads that do not contain quote characters. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2026-2231 (CVSS 7.2)

The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2019-25650 (CVSS 8.4)

River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll name field. Attackers can craft a payload with a 280-byte buffer, NSEH jump instruction, and SEH handler address pointing to a pop-pop-ret gadget to trigger code execution and establish a bind shell on port 3110.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25219 (CVSS 8.4)

PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that triggers code execution when pasted into the Licensed E-mail and Registration Code field during the registration process.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25218 (CVSS 8.4)

PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into the 'Licensed E-mail and Registration Code' field during registration to trigger code execution.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25217 (CVSS 8.4)

PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields settings dialog processes the malicious input in the Label field.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25213 (CVSS 8.4)

Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field to achieve code execution with application privileges.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25212 (CVSS 8.4)

Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows attackers to execute arbitrary code by crafting malicious WAV files. Attackers can create a specially crafted WAV file with excessive data and ROP gadgets to overwrite the SEH chain and achieve code execution on Windows systems.

NVD (NIST)26 mar 2026

Pagina 2689 di 3345

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.