Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45857 risultati

VulnerabilitàAlta
CVE-2026-92574 (CVSS 8.8)

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-92574 - Cri-o: cri-o checkpoint restore bypasses destination security context

CVE ID :CVE-2026-92574 Published : Sept. 21, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-91921 - Cross-Site Scripting (XSS) in 1millionbot’s AI chatbot platform

CVE ID :CVE-2026-91921 Published : Sept. 21, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the web interface by sending messages containing Markdown syntax and certain unsanitised content blocks. The impact is limited to the user’s own interactive session; no compromise of internal infrastructure, access to third-party data or impact on administrative panels has been identified. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94277 - Stored Cross-Site Scripting in MISP Galaxy Matrix Statistics via Unescaped Galaxy Name

CVE ID :CVE-2026-94277 Published : Sept. 21, 2026, 10:17 a.m. | 2 hours, 10 minutes ago Description :MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the perm_galaxy_editor permission can create or modify a galaxy whose name contains arbitrary HTML or JavaScript markup. Because the value is interpolated verbatim into the page, any user who subsequently opens the galaxy matrix statistics page will have the embedded script executed in their browser context. This enables session hijacking, credential theft, data exfiltration, or the performance of arbitrary actions on behalf of the victim within the MISP application. Version affected: Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94151 - Omega Solution HRM OS Role Permission API permission missing authentication

CVE ID :CVE-2026-94151 Published : Sept. 21, 2026, 9:17 a.m. | 3 hours, 10 minutes ago Description :A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can lead to missing authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94152 - Omega Solution FBP Fulfillment by People User Profile API user authorization

CVE ID :CVE-2026-94152 Published : Sept. 21, 2026, 9:17 a.m. | 3 hours, 10 minutes ago Description :A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94150 - Omega Solution HRM OS SVG File Upload view cross site scripting

CVE ID :CVE-2026-94150 Published : Sept. 21, 2026, 9:17 a.m. | 3 hours, 10 minutes ago Description :A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-92400 - Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion

CVE ID :CVE-2026-92400 Published : Sept. 21, 2026, 9:17 a.m. | 3 hours, 10 minutes ago Description :The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own orders as paid using a genuine transaction from a payment sandbox they control. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-85113 - GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name

CVE ID :CVE-2026-85113 Published : Sept. 21, 2026, 9:17 a.m. | 56 minutes ago Description :The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-86802 - To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import

CVE ID :CVE-2026-86802 Published : Sept. 21, 2026, 9:17 a.m. | 3 hours, 10 minutes ago Description :The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-15801 (CVSS 8)

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is enabled, which is not the default configuration. An attacker must also be able to trigger restoration of a container from untrusted checkpoint content.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-85010 - RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons

CVE ID :CVE-2026-85010 Published : Sept. 21, 2026, 9:17 a.m. | 56 minutes ago Description :The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026

Pagina 297 di 3822

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.