Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45930 risultati

VulnerabilitàAlta
CVE-2026-94038 (CVSS 7.3)

A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 8389032e5d52c28c4855c6126ca7d0eae8af346a. It is best practice to apply a patch to resolve this issue.

NVD (NIST)20 set 2026
VulnerabilitàAlta
CVE-2026-94038 - NonceGeek dim-sum-app Deno Backend main.tsx textSearchV2Handler server-side request forgery

CVE ID :CVE-2026-94038 Published : Sept. 20, 2026, 5:16 p.m. | 4 hours, 50 minutes ago Description :A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 8389032e5d52c28c4855c6126ca7d0eae8af346a. It is best practice to apply a patch to resolve this issue. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94037 - 00Kisumi00 mcp-file-analyzer analyze_csv_data MCP tool main.py ControlFlowNode path traversal

CVE ID :CVE-2026-94037 Published : Sept. 20, 2026, 5:16 p.m. | 4 hours, 50 minutes ago Description :A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the file main.py of the component analyze_csv_data MCP tool. This manipulation of the argument filename causes path traversal. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94040 - vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery

CVE ID :CVE-2026-94040 Published : 20. September 2026 17:16 | 7 Stunden, 10 Minuten ago Description :A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/baseUrl can lead to server-side request forgery. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94039 - vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery

CVE ID :CVE-2026-94039 Published : Sept. 20, 2026, 5:16 p.m. | 4 hours, 50 minutes ago Description :A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94041 - AdithyaYelloju Restaurant-Management-System add_menu.php sql injection

CVE ID :CVE-2026-94041 Published : 20. September 2026 18:16 | 6 Stunden, 10 Minuten ago Description :A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the argument item/price/image/type leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94036 (CVSS 8.8)

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.

NVD (NIST)20 set 2026
VulnerabilitàAlta
CVE-2026-94036 - D-Link DIR-X1860/DIR-X1860Z routerd ubus access control

CVE ID :CVE-2026-94036 Published : Sept. 20, 2026, 4:16 p.m. | 5 hours, 50 minutes ago Description :A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94034 - SourceCodester Drug Recommendation System Password Change change_password cross site scripting

CVE ID :CVE-2026-94034 Published : Sept. 20, 2026, 3:16 p.m. | 6 hours, 51 minutes ago Description :A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94033 - SourceCodester Drug Recommendation System User Management add_user cross site scripting

CVE ID :CVE-2026-94033 Published : Sept. 20, 2026, 3:16 p.m. | 6 hours, 51 minutes ago Description :A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txtname/txtemail/txtpassword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94032 - itsourcecode Leave Management System index.php sql injection

CVE ID :CVE-2026-94032 Published : Sept. 20, 2026, 3:16 p.m. | 6 hours, 51 minutes ago Description :A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94035 - SourceCodester Drug Recommendation System index.php cross site scripting

CVE ID :CVE-2026-94035 Published : Sept. 20, 2026, 4:16 p.m. | 5 hours, 50 minutes ago Description :A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026

Pagina 310 di 3828

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.