Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45538 risultati

VulnerabilitàAlta
CVE-2026-4580 (CVSS 7.3)

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php of the component Parameters Handler. The manipulation of the argument serviceId results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-4580 - code-projects Simple Laundry System Parameters checkupdatestatus.php sql injection

CVE ID :CVE-2026-4580 Published : March 23, 2026, 9:16 a.m. | 4 hours, 36 minutes ago Description :A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php of the component Parameters Handler. The manipulation of the argument serviceId results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
News
CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks

CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks CISA Warns Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain An urgent warning regarding three critical Apple vulnerabilities that threat actors are actively exploiting in the wild. These se ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2025-43520 CVE-2025-43510 CVE-2025-31277

CVEfeed Newsroom23 mar 2026
News
The Undocumented Backdoor: Critical 10.0 CVSS Flaw Hits WAGO Managed Switches

The Undocumented Backdoor: Critical 10.0 CVSS Flaw Hits WAGO Managed Switches A severe vulnerability has been uncovered in several models of WAGO Managed Switches, potentially leaving industrial networks exposed to complete takeover. The flaw, tracked as CVE-2026-3587, has earn ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-3587 CVE-2025-32432

CVEfeed Newsroom23 mar 2026
VulnerabilitàAlta
CVE-2026-4579 (CVSS 7.3)

A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the component Parameters Handler. The manipulation of the argument serviceId leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

NVD (NIST)23 mar 2026
VulnerabilitàCritica
CVE-2026-3587 (CVSS 10)

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface and gain root access to the underlying Linux based OS, leading to full compromise of the device.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-3587 - Hidden CLI Function Allows Root Access

CVE ID :CVE-2026-3587 Published : March 23, 2026, 8:16 a.m. | 3 hours, 36 minutes ago Description :An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface and gain root access to the underlying Linux based OS, leading to full compromise of the device. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4579 - code-projects Simple Laundry System Parameters viewdetail.php sql injection

CVE ID :CVE-2026-4579 Published : March 23, 2026, 8:16 a.m. | 5 hours, 36 minutes ago Description :A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the component Parameters Handler. The manipulation of the argument serviceId leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4578 - code-projects Exam Form Submission update_s3.php cross site scripting

CVE ID :CVE-2026-4578 Published : March 23, 2026, 8:16 a.m. | 5 hours, 36 minutes ago Description :A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_s3.php. Executing a manipulation of the argument sname can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4577 - code-projects Exam Form Submission update_s4.php cross site scripting

CVE ID :CVE-2026-4577 Published : March 23, 2026, 7:16 a.m. | 4 hours, 36 minutes ago Description :A vulnerability was found in code-projects Exam Form Submission 1.0. The affected element is an unknown function of the file /admin/update_s4.php. Performing a manipulation of the argument sname results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-23554 - Use after free of paging structures in EPT

CVE ID :CVE-2026-23554 Published : March 23, 2026, 7:16 a.m. | 4 hours, 36 minutes ago Description :The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush. Freeing of paging structures however is not deferred until the flushing is done, and can result in freed pages transiently being present in cached state. Such stale entries can point to memory ranges not owned by the guest, thus allowing access to unintended memory regions. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-23555 - Xenstored DoS by unprivileged domain

CVE ID :CVE-2026-23555 Published : March 23, 2026, 7:16 a.m. | 4 hours, 36 minutes ago Description :Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenstored when verifying the node path. Note that the crash is forced via a failing assert() statement in xenstored. In case xenstored is being built with NDEBUG #defined, an unprivileged guest trying to access the node path "/local/domain/" will result in it no longer being serviced by xenstored, other guests (including dom0) will still be serviced, but xenstored will use up all cpu time it can get. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026

Pagina 3204 di 3795

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.