Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

46026 risultati

VulnerabilitàAlta
CVE-2026-94106 (CVSS 8.8)

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.

NVD (NIST)20 set 2026
VulnerabilitàAlta
CVE-2026-94106 - getID3 before 1.9.26 OS Command Injection via Unescaped Filenames

CVE ID :CVE-2026-94106 Published : Sept. 20, 2026, 12:17 p.m. | 3 hours, 58 minutes ago Description :getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94107 - NivoCart through 2.4.0 Predictable Administrator Password Reset Token

CVE ID :CVE-2026-94107 Published : Sept. 20, 2026, 12:17 p.m. | 3 hours, 58 minutes ago Description :NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94109 - openEQUELLA before 2026.1.0 Remote Code Execution via FreeMarker Template Injection

CVE ID :CVE-2026-94109 Published : Sept. 20, 2026, 12:17 p.m. | 3 hours, 58 minutes ago Description :openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates to instantiate dangerous classes like freemarker.template.utility.Execute and invoke Runtime.exec for arbitrary command execution. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94104 (CVSS 8.8)

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office access can upload PHP files to the web-accessible image/data/ directory and execute them for remote code execution.

NVD (NIST)20 set 2026
VulnerabilitàAlta
CVE-2026-94004 (CVSS 7.3)

A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument aid results in code injection. The attack can be launched remotely. The exploit has been made public and could be used.

NVD (NIST)20 set 2026
VulnerabilitàCritica
CVE-2026-94003 (CVSS 10)

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD (NIST)20 set 2026
VulnerabilitàAlta
CVE-2026-93997 (CVSS 7.3)

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

NVD (NIST)20 set 2026
VulnerabilitàAlta
CVE-2026-94003 - Comfast CF-N1-S Web Management mbox-config get_css_path_from_uri stack-based overflow

CVE ID :CVE-2026-94003 Published : Sept. 20, 2026, 12:17 p.m. | 3 hours, 58 minutes ago Description :A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94104 - NivoCart through 2.4.0 Arbitrary File Upload RCE via filemanager

CVE ID :CVE-2026-94104 Published : Sept. 20, 2026, 12:17 p.m. | 3 hours, 58 minutes ago Description :NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office access can upload PHP files to the web-accessible image/data/ directory and execute them for remote code execution. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-94004 - DedeCMS mytag_js.php code injection

CVE ID :CVE-2026-94004 Published : Sept. 20, 2026, 12:17 p.m. | 3 hours, 58 minutes ago Description :A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument aid results in code injection. The attack can be launched remotely. The exploit has been made public and could be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026
VulnerabilitàAlta
CVE-2026-93997 - SourceCodester Drug Recommendation System edit_symptom.php sql injection

CVE ID :CVE-2026-93997 Published : Sept. 20, 2026, 12:17 p.m. | 2 hours, 10 minutes ago Description :A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE20 set 2026

Pagina 320 di 3836

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.