Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

40588 risultati

VulnerabilitàAlta
CVE-2018-25206 (CVSS 8.2)

KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_item_search' parameter in edit.php. Attackers can submit POST requests with malicious SQL payloads to extract sensitive database information using boolean-based blind or error-based injection techniques.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25205 (CVSS 8.2)

ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Attackers can submit malicious SQL payloads via GET or POST requests to the /search endpoint to extract sensitive database information using boolean-based blind or error-based techniques.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25204 (CVSS 8.2)

Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can send POST requests to the admin login endpoint with boolean-based blind SQL injection payloads in the username field to manipulate database queries and gain unauthorized access.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25203 (CVSS 8.2)

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind or time-based blind SQL injection payloads in the email field to extract sensitive database information.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25202 (CVSS 8.2)

SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id' parameter in the signIn endpoint. Attackers can submit POST requests with boolean-based blind, stacked queries, or time-based blind SQL injection payloads to extract sensitive data or compromise the application.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25201 (CVSS 7.1)

School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious payloads using boolean-based blind SQL injection techniques to the processlogin endpoint to authenticate as administrator without valid credentials.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25195 (CVSS 8.2)

Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25185 (CVSS 8.2)

Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind or time-based blind techniques to extract sensitive database information.

NVD (NIST)26 mar 2026
VulnerabilitàAlta
CVE-2018-25183 (CVSS 8.2)

Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious SQL payloads using boolean-based blind techniques in POST requests to the admin login endpoint to authenticate without valid credentials.

NVD (NIST)26 mar 2026
News
Synology DiskStation Manager Vulnerability Allow Remote Attackers to Execute Arbitrary Commands

Synology DiskStation Manager Vulnerability Allow Remote Attackers to Execute Arbitrary Commands A critical security advisory has been issued for a severe vulnerability in DiskStation Manager (DSM) that allows unauthenticated remote attackers to execute arbitrary commands. Given the widespread us ... Read more Published Date: Mar 26, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32746

CVEfeed Newsroom26 mar 2026
VulnerabilitàAlta
CVE-2026-4274 - Insufficient authorization in shared channel membership sync grants team-level access instead of channel-level access

CVE ID :CVE-2026-4274 Published : March 26, 2026, 11:16 a.m. | 36 minutes ago Description :Mattermost versions 11.2.x Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-4809 - Unsafe Client MIME Type Handling Can Enable Arbitrary File Upload in plank/laravel-mediable

CVE ID :CVE-2026-4809 Published : March 26, 2026, 11:16 a.m. | 36 minutes ago Description :plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload. If the uploaded file is stored in a web-accessible and executable location, this may lead to remote code execution. At the time of publication, no patch was available and the vendor had not responded to coordinated disclosure attempts. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026

Pagina 2731 di 3383

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.