Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45538 risultati

VulnerabilitàAlta
CVE-2025-41007 - SQL Injection in Cuantis

CVE ID :CVE-2025-41007 Published : March 23, 2026, 1:16 p.m. | 35 minutes ago Description :SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'search' parameter in the '/search.php' endpoint. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
News
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories. This edition covers a ... Read more Published Date: Mar 23, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-3864 CVE-2026-31382 CVE-2026-31381 CVE-2026-33017 CVE-2026-21992 CVE-2026-4441 CVE-2026-4440 CVE-2026-4439 CVE-2026-22558 CVE-2026-22557 CVE-2026-33002 CVE-2026-33001 CVE-2026-20643 CVE-2026-32298 CVE-2026-32297 CVE-2026-25769 CVE-2026-21570 CVE-2026-3564 CVE-2026-3888 CVE-2026-4276 CVE-2026-32635 CVE-2026-32746 CVE-2026-24291 CVE-2026-20131 CVE-2026-26189 CVE-2026-21643 CVE-2026-21884 CVE-2025-14986

CVEfeed Newsroom23 mar 2026
News
Roundcube Webmail Hits Critical Update: New Security Fixes Target Hidden Vulnerabilities

Roundcube Webmail Hits Critical Update: New Security Fixes Target Hidden Vulnerabilities Roundcube Webmail has released a high-priority security update, version 1.6.14, aimed at patching several significant vulnerabilities that could put user data and server integrity at risk. This stable ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2025-32432 CVE-2023-5631

CVEfeed Newsroom23 mar 2026
VulnerabilitàAlta
CVE-2025-41008 - SQL Injection in Sinturno

CVE ID :CVE-2025-41008 Published : March 23, 2026, 2:16 p.m. | 1 hour, 35 minutes ago Description :SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'client' parameter in the '/_adm/scripts/modalReport_data.php' endpoint. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàCritica
CVE-2026-4585 (CVSS 9.8)

A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/ImportSystemConfiguration.jsp of the component Configuration Handler. The manipulation of the argument File leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-32969 (CVSS 7.5)

An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

NVD (NIST)23 mar 2026
VulnerabilitàCritica
CVE-2026-32968 (CVSS 9.8)

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-31846 - Nexxt Solutions Nebula 300+ Unauthenticated Credential Disclosure Vulnerability

CVE ID :CVE-2026-31846 Published : March 23, 2026, 12:16 p.m. | 1 hour, 36 minutes ago Description :An unauthenticated credential disclosure vulnerability in the /goform/ate endpoint of Nexxt Solutions Nebula 300+ firmware through Nebula300+_v12.01.01.37 allows an adjacent attacker to obtain the administrator password in Base64-encoded form via a crafted HTTP request. The recovered credential can be used to authenticate to the device and facilitates further compromise when combined with other weaknesses present in the firmware. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4633 - Keycloak: keycloak: user enumeration via differential error messages

CVE ID :CVE-2026-4633 Published : March 23, 2026, 11:16 a.m. | 2 hours, 35 minutes ago Description :A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
News
CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks A critical vulnerability in Craft CMS (CVE-2025-32432) has been added to the Known Exploited Vulnerabilities catalog following confirmed active exploitation in the wild. Security teams and system admi ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2025-32432

CVEfeed Newsroom23 mar 2026
VulnerabilitàAlta
CVE-2026-28809 - XXE in esaml SAML library allows local file read and potential SSRF

CVE ID :CVE-2026-28809 Published : March 23, 2026, 11:16 a.m. | 2 hours, 36 minutes ago Description :XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled SAML messages using xmerl_scan:string/2 before signature verification without disabling XML entity expansion. On Erlang/OTP versions before 27, Xmerl allows entities by default, enabling pre-signature XXE attacks. An attacker can cause the host to read local files (e.g., Kubernetes-mounted secrets) into the SAML document. If the attacker is not a trusted SAML SP, signature verification will fail and the document is discarded, but file contents may still be exposed through logs or error messages. This issue affects all versions of esaml, including forks by arekinath, handnot2, and dropbox. Users running on Erlang/OTP 27 or later are not affected due to Xmerl defaulting to entities disabled. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4583 - Shenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replay

CVE ID :CVE-2026-4583 Published : March 23, 2026, 11:16 a.m. | 2 hours, 36 minutes ago Description :A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown functionality of the component Bluetooth Handler. Performing a manipulation results in authentication bypass by capture-replay. The attack must originate from the local network. The attack is considered to have high complexity. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026

Pagina 3202 di 3795

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.