Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45548 risultati

VulnerabilitàAlta
CVE-2026-4568 - SourceCodester Sales and Inventory System HTTP GET Request update_supplier.php sql injection

CVE ID :CVE-2026-4568 Published : March 23, 2026, 3:16 a.m. | 2 hours, 36 minutes ago Description :A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /update_supplier.php of the component HTTP GET Request Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. Several companies clearly confirm that VulDB is the primary source for best vulnerability data. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4569 - SourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injection

CVE ID :CVE-2026-4569 Published : March 23, 2026, 4:16 a.m. | 1 hour, 36 minutes ago Description :A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /view_category.php of the component HTTP POST Request Handler. This manipulation of the argument searchtxt causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
News
The Weekly Breach: 7 Maximum CVSS Flaws and the DarkSword Exploit Unveiled

The Weekly Breach: 7 Maximum CVSS Flaws and the DarkSword Exploit Unveiled The past seven days have been an exceptionally busy period for cybersecurity defenders. Between March 16 and March 23, a staggering 1,348 new vulnerabilities were identified and logged. While the shee ... Read more Published Date: Mar 23, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4565 CVE-2026-2580 CVE-2026-4558 CVE-2026-32169 CVE-2026-30836 CVE-2026-22557 CVE-2026-0866 CVE-2026-20131 CVE-2026-2256 CVE-2026-27699 CVE-2025-62878 CVE-2025-30411 CVE-2026-1358 CVE-2025-26385 CVE-2026-1453 CVE-2026-23830 CVE-2025-14988 CVE-2026-0994 CVE-2026-0695 CVE-2025-61937 CVE-2025-37186 CVE-2025-52691 CVE-2025-37164 CVE-2025-43520 CVE-2025-43510 CVE-2025-59396 CVE-2025-58384 CVE-2025-31277 CVE-2025-54068 CVE-2025-32432 CVE-2025-1316 CVE-1999-0073

CVEfeed Newsroom23 mar 2026
VulnerabilitàAlta
CVE-2026-4565 (CVSS 8.8)

A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-4565 - Tenda AC21 SetNetControlList formSetQosBand buffer overflow

CVE ID :CVE-2026-4565 Published : March 23, 2026, 1:16 a.m. | 4 hours, 35 minutes ago Description :A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4606 - GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege

CVE ID :CVE-2026-4606 Published : March 23, 2026, 2:16 a.m. | 3 hours, 36 minutes ago Description :GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system. During installation, ERM creates a Windows service that runs under the LocalSystem account. When the ERM application is launched, related processes are spawned under SYSTEM privileges rather than the security context of the logged-in user. Functions such as 'Import Data' open a Windows file dialog operating with SYSTEM permissions, enabling modification or deletion of protected system files and directories. Any ERM function invoking Windows file open/save dialogs exposes the same risk. This vulnerability allows local privilege escalation and may result in full system compromise. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4564 - yangzongzhuan RuoYi Quartz Job job code injection

CVE ID :CVE-2026-4564 Published : March 23, 2026, 12:16 a.m. | 5 hours, 35 minutes ago Description :A security vulnerability has been detected in yangzongzhuan RuoYi up to 4.8.2. This issue affects some unknown processing of the file /monitor/job/ of the component Quartz Job Handler. Such manipulation of the argument invokeTarget leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4562 (CVSS 7.3)

A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-2580 (CVSS 7.5)

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-4563 - MacCMS Member Order Detail User.php order_info authorization

CVE ID :CVE-2026-4563 Published : March 23, 2026, 12:16 a.m. | 5 hours, 35 minutes ago Description :A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization bypass. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-2580 - WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter

CVE ID :CVE-2026-2580 Published : March 23, 2026, 12:16 a.m. | 3 hours, 35 minutes ago Description :The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4562 - MacCMS Timming API Endpoint Timming.php weak authentication

CVE ID :CVE-2026-4562 Published : March 23, 2026, 12:16 a.m. | 3 hours, 35 minutes ago Description :A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026

Pagina 3208 di 3796

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.