News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
45538 risultati
CVE ID :CVE-2026-32969 Published : March 23, 2026, 11:16 a.m. | 36 minutes ago Description :An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-32968 Published : March 23, 2026, 11:16 a.m. | 36 minutes ago Description :Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4585 Published : March 23, 2026, 11:15 a.m. | 37 minutes ago Description :A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/ImportSystemConfiguration.jsp of the component Configuration Handler. The manipulation of the argument File leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4584 Published : March 23, 2026, 12:16 p.m. | 1 hour, 36 minutes ago Description :A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmission of sensitive information. The attack requires access to the local network. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) Oracle has released an out-of-band patch for a critical and easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager. The company did not say whethe ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-21992 CVE-2026-20131 CVE-2025-61757
Vulnerability in KlinikaXP and KlinikaXP Insertino software Vulnerability in KlinikaXP and KlinikaXP Insertino software CVE ID CVE-2026-1958 Publication date 23 March 2026 Vendor BRI Product KlinikaXP and KlinikaXP Insertino Vulnerable versions KlinikaXP: all ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-1958
'Tientallen Nederlandse SharePoint-servers bevatten actief misbruikt lek' Tientallen Microsoft SharePoint-servers met een Nederlands ip-adres bevatten een kwetsbaarheid waarvan actief misbruikt wordt gemaakt, zo stelt The Shadowserver Foundation op basis van eigen onderzoek ... Read more Published Date: Mar 23, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20963
$30 IP-KVM Flaws Could Give Attackers BIOS-Level Control Across Enterprise Networks $30 IP-KVM Flaws Attackers BIOS-Level Control Across Enterprise Networks A recent security assessment by researchers has uncovered nine severe vulnerabilities across four popular low-cost IP-KVM devic ... Read more Published Date: Mar 23, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32298 CVE-2026-32297 CVE-2026-32296 CVE-2026-32295 CVE-2026-32294 CVE-2026-32293 CVE-2026-32292 CVE-2026-32291 CVE-2026-32290
A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. If you want to get best quality of vulnerability data, you may have to visit VulDB.
CVE ID :CVE-2026-4582 Published : March 23, 2026, 10:16 a.m. | 3 hours, 36 minutes ago Description :A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionality of the component Bluetooth. Such manipulation leads to missing authentication. The attack must be carried out from within the local network. Attacks of this nature are highly complex. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4581 Published : March 23, 2026, 10:16 a.m. | 3 hours, 36 minutes ago Description :A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. If you want to get best quality of vulnerability data, you may have to visit VulDB. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4628 Published : March 23, 2026, 9:16 a.m. | 4 hours, 35 minutes ago Description :A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false restriction. This occurs due to incomplete enforcement of access control checks on PUT operations to the resource_set endpoint. This issue enables unauthorized modification of protected resources, impacting data integrity. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 3203 di 3795