Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

40682 risultati

VulnerabilitàAlta
CVE-2026-4075 - BWL Advanced FAQ Manager Lite <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sbox_id' Shortcode Attribute

CVE ID :CVE-2026-4075 Published : March 26, 2026, 4:17 a.m. | 1 hour, 35 minutes ago Description :The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up to and including 1.1.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'sbox_id', 'sbox_class', 'placeholder', 'highlight_color', 'highlight_bg', and 'cont_ext_class'. These attributes are directly interpolated into HTML element attributes without any esc_attr() escaping in the baf_sbox() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-1986 - FloristPress for Woo <= 7.8.2 - Reflected Cross-Site Scripting via 'noresults' Parameter

CVE ID :CVE-2026-1986 Published : March 26, 2026, 4:17 a.m. | 1 hour, 35 minutes ago Description :The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'noresults' parameter in all versions up to, and including, 7.8.2 due to insufficient input sanitization and output escaping on the user supplied 'noresults' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-3328 - Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts

CVE ID :CVE-2026-3328 Published : March 26, 2026, 2:25 a.m. | 1 hour, 27 minutes ago Description :The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's `maybe_unserialize()` function without class restrictions on user-controllable content stored in admin_form post content. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàCritica
CVE-2026-4484 (CVSS 9.8)

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with Student-level access and above, to elevate their privileges to that of an administrator.

NVD (NIST)26 mar 2026
News
Apple Patches numerous vulnerabilities across its products

Apple Patches numerous vulnerabilities across its products Apple’s latest security update wave — covering iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, watchOS 26.4, tvOS 26.4, visionOS 26.4, Safari 26.4, and Xcode 26.4 — resolves over 85 vulnerabilities. No activ ... Read more Published Date: Mar 26, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-28886 CVE-2026-28868 CVE-2026-28865 CVE-2026-20688 CVE-2026-3055 CVE-2026-20678 CVE-2026-20655 CVE-2026-20616 CVE-2026-20609

CVEfeed Newsroom26 mar 2026
News
NVIDIA Patches Critical RCE and DoS Flaws Across ML Frameworks

NVIDIA Patches Critical RCE and DoS Flaws Across ML Frameworks NVIDIA has released a series of critical software updates to address high-severity vulnerabilities across its core AI and machine learning frameworks. The patches cover Megatron-LM, Triton Inference S ... Read more Published Date: Mar 26, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-24158 CVE-2026-24157 CVE-2026-24141 CVE-2025-33247 CVE-2025-33217 CVE-2025-33228 CVE-2025-23358 CVE-2025-23316 CVE-2025-29969 CVE-2024-0148 CVE-2024-0136 CVE-2024-0130 CVE-2024-1024

CVEfeed Newsroom26 mar 2026
News
Public Flaws in Cisco IOx Allow Unauthenticated Log Injection and Admin XSS

Public Flaws in Cisco IOx Allow Unauthenticated Log Injection and Admin XSS Cisco has issued security advisories regarding two vulnerabilities in its Cisco IOx application hosting environment for Cisco IOS XE Software. The flaws, which include a stored cross-site scripting (X ... Read more Published Date: Mar 26, 2026 (1 day, 7 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20113 CVE-2026-20112 CVE-2026-1995 CVE-2026-20045 CVE-2025-20363 CVE-2025-20352 CVE-2025-29969 CVE-2024-20470 CVE-2024-20393

CVEfeed Newsroom26 mar 2026
VulnerabilitàAlta
CVE-2026-4484 - Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator

CVE ID :CVE-2026-4484 Published : March 26, 2026, 2:16 a.m. | 3 hours, 36 minutes ago Description :The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with Student-level access and above, to elevate their privileges to that of an administrator. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-33942 - Saloon has insecure deserialization in AccessTokenAuthenticator (object injection / RCE)

CVE ID :CVE-2026-33942 Published : March 26, 2026, 1:16 a.m. | 2 hours, 36 minutes ago Description :Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAuthenticator::unserialize() to restore OAuth token state from cache or storage, with allowed_classes => true. An attacker who can control the serialized string (e.g. by overwriting a cached token file or via another injection) can supply a serialized "gadget" object. When unserialize() runs, PHP instantiates that object and runs its magic methods (__wakeup, __destruct, etc.), leading to object injection. In environments with common dependencies (e.g. Monolog), this can be chained to remote code execution (RCE). The fix in version 4.0.0 removes PHP serialization from the AccessTokenAuthenticator class requiring users to store and resolve the authenticator manually. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-4830 - kalcaddle kodbox Public Share userShare.class.php add privilege escalation

CVE ID :CVE-2026-4830 Published : March 26, 2026, 1:16 a.m. | 4 hours, 36 minutes ago Description :A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-33287 - LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

CVE ID :CVE-2026-33287 Published : March 26, 2026, 1:16 a.m. | 2 hours, 36 minutes ago Description :LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS uses JavaScript's `String.prototype.replace()` which interprets `$&` as a back reference to the matched substring. The filter only charges `memoryLimit` for the input string length, not the amplified output. An attacker can achieve exponential memory amplification (up to 625,000:1) while staying within the `memoryLimit` budget, leading to denial of service. Version 10.25.1 patches the issue. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-33515 - Squid has issues in ICP message handling

CVE ID :CVE-2026-33515 Published : March 26, 2026, 1:16 a.m. | 2 hours, 36 minutes ago Description :Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of memory potentially containing sensitive information when responding with errors to invalid ICP requests. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem cannot be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026

Pagina 2745 di 3391

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.