Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

40779 risultati

VulnerabilitàAlta
CVE-2026-34055 - OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification

CVE ID :CVE-2026-34055 Published : March 26, 2026, 12:16 a.m. | 1 hour, 36 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without verifying that the note belongs to a patient the user is authorized to access. Multiple web UI callers pass user-controlled note IDs directly to these functions. This is the same class of vulnerability as CVE-2026-25745 (REST API IDOR), but affects the web UI code paths. Version 8.0.0.3 patches the issue. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-34051 - OpenEMR has Improper ACL On Import/Export Popup

CVE ID :CVE-2026-34051 Published : March 26, 2026, 12:16 a.m. | 1 hour, 36 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct request manipulation despite UI restrictions. This can lead to unauthorized data access, bulk data extraction, and manipulation of system data. Version 8.0.0.3 contains a fix. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-33933 - Reflected XSS via Unescaped contextName Parameter in Custom Template Editor

CVE ID :CVE-2026-33933 Published : March 26, 2026, 12:16 a.m. | 1 hour, 36 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute arbitrary JavaScript in an authenticated staff member's browser session by sending them a crafted URL. The attacker does not need an OpenEMR account. Version 8.0.0.3 patches the issue. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-33934 - OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures

CVE ID :CVE-2026-33934 Published : March 26, 2026, 12:16 a.m. | 1 hour, 36 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal user to retrieve the drawn signature image of any staff member by supplying an arbitrary `user` value in the POST body. The companion write endpoint (`save-signature.php`) was already hardened against this same issue, but the read endpoint was not updated to match. Version 8.0.0.3 patches the issue. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
VulnerabilitàAlta
CVE-2026-33932 - OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes

CVE ID :CVE-2026-33932 Published : March 26, 2026, 12:16 a.m. | 1 hour, 36 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CCDA document to execute arbitrary JavaScript in a clinician's browser session when the document is previewed. The XSL stylesheet sanitizes attributes for all other narrative elements but not for `linkHtml`, allowing `href="javascript:..."` and event handler attributes to pass through unchanged. Version 8.0.0.3 patches the issue. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE26 mar 2026
News
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities Key takeaways: Prolific Russia-aligned Advanced Persistent Threat (APT) group Pawn Storm has been using PRISMEX, a collection of interconnected malware components to target the defense supply chain of ... Read more Published Date: Mar 26, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-21513 CVE-2026-21509

CVEfeed Newsroom26 mar 2026
News
Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise

Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise Artificial Intelligence (AI) TeamPCP orchestrated one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date that cascaded through developer tooling and compromis ... Read more Published Date: Mar 26, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-3400

CVEfeed Newsroom26 mar 2026
VulnerabilitàAlta
CVE-2026-33931 - OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access

CVE ID :CVE-2026-33931 Published : March 26, 2026, 12:16 a.m. | 1 hour, 36 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' payment records — including invoice/billing data (PHI) and payment card metadata — by manipulating the `recid` query parameter in `portal/portal_payment.php`. Version 8.0.0.3 patches the issue. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
VulnerabilitàAlta
CVE-2026-4826 - SourceCodester Sales and Inventory System HTTP GET Parameter update_stock.php sql injection

CVE ID :CVE-2026-4826 Published : March 26, 2026, 12:16 a.m. | 3 hours, 36 minutes ago Description :A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /update_stock.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. If you want to get best quality of vulnerability data, you may have to visit VulDB. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
VulnerabilitàAlta
CVE-2026-33918 - OpenEMR Missing Authorization on Claim File Download Endpoint

CVE ID :CVE-2026-33918 Published : March 26, 2026, 12:16 a.m. | 1 hour, 36 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does not check any ACL permissions. This allows any authenticated OpenEMR user — regardless of whether they have billing privileges — to download and permanently delete electronic claim batch files containing protected health information (PHI). Version 8.0.0.3 patches the issue. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
VulnerabilitàAlta
CVE-2026-33917 - OpenEMR has SQL Injection in CAMOS Form

CVE ID :CVE-2026-33917 Published : March 26, 2026, 12:16 a.m. | 1 hour, 36 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the ajax_save page in the CAMOS form. Version 8.0.0.3 patches the issue. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026
VulnerabilitàAlta
CVE-2026-4758 - WP Job Portal <= 2.4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field

CVE ID :CVE-2026-4758 Published : March 26, 2026, 12:16 a.m. | 3 hours, 36 minutes ago Description :The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE25 mar 2026

Pagina 2755 di 3399

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.