Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45524 risultati

VulnerabilitàAlta
CVE-2019-25622 - Paint Studio 2.17 Denial of Service via Malformed Input

CVE ID :CVE-2019-25622 Published : March 23, 2026, 2:16 p.m. | 1 hour, 35 minutes ago Description :Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of characters and trigger the application to read it, causing the application to crash and become unavailable. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4588 - kalcaddle kodbox Site-level API key shareOut.class.php shareSafeGroup hard-coded key

CVE ID :CVE-2026-4588 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-level API key Handler. This manipulation of the argument sk causes use of hard-coded cryptographic key . The attack may be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4586 - CodePhiliaX Chat2DB JDBC Driver Upload JdbcDriverController.java upload unrestricted upload

CVE ID :CVE-2026-4586 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/server/web/api/controller/driver/JdbcDriverController.java of the component JDBC Driver Upload. Performing a manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4587 - HybridAuth SSL Curl.php certificate validation

CVE ID :CVE-2026-4587 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpClient/Curl.php of the component SSL Handler. The manipulation of the argument curlOptions results in improper certificate validation. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-31851 - Lack of rate limiting allows brute-force attacks in Nexxt Nebula 300+

CVE ID :CVE-2026-31851 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout on the authentication interface. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-1958 - Hard-coded passwords in KlinikaXP

CVE ID :CVE-2026-1958 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update. This issue affects KlinikaXP: before 5.39.01.01. and KlinikaXP Insertino before 3.1.0.1 Beside removing the hardcoded credentials from the code, previously exposed credentials were also rotated preventing further attack attempts. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-31847 - Hidden functionality allows remote Telnet enablement in Nexxt Nebula 300+

CVE ID :CVE-2026-31847 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. Once enabled, the service exposes a privileged diagnostic management interface over the network, increasing the attack surface and enabling further compromise of the device. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-31848 - Reversible ecos_pw cookie allows administrative authentication in Nexxt Nebula 300+

CVE ID :CVE-2026-31848 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores administrative authentication material in the ecos_pw cookie using a reversible Base64-encoded format with a static suffix. An attacker who obtains or derives this cookie value can forge a valid administrative session and gain unauthorized access to the device. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-31849 - Missing CSRF protection on state-changing endpoints in Nexxt Nebula 300+

CVE ID :CVE-2026-31849 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing administrative endpoints. A remote attacker can induce an authenticated administrator to submit crafted requests that modify device settings, including security-relevant configuration, without the administrator's intent. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-31850 - Plaintext storage of credentials in configuration backup in Nexxt Nebula 300+

CVE ID :CVE-2026-31850 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative credentials and WiFi pre-shared keys, in plaintext within exported configuration backup files. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2025-41007 - SQL Injection in Cuantis

CVE ID :CVE-2025-41007 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'search' parameter in the '/search.php' endpoint. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
News
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories. This edition covers a ... Read more Published Date: Mar 23, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-3864 CVE-2026-31382 CVE-2026-31381 CVE-2026-33017 CVE-2026-21992 CVE-2026-4441 CVE-2026-4440 CVE-2026-4439 CVE-2026-22558 CVE-2026-22557 CVE-2026-33002 CVE-2026-33001 CVE-2026-20643 CVE-2026-32298 CVE-2026-32297 CVE-2026-25769 CVE-2026-21570 CVE-2026-3564 CVE-2026-3888 CVE-2026-4276 CVE-2026-32635 CVE-2026-32746 CVE-2026-24291 CVE-2026-20131 CVE-2026-26189 CVE-2026-21643 CVE-2026-21884 CVE-2025-14986

CVEfeed Newsroom23 mar 2026

Pagina 3200 di 3794

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.