Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45548 risultati

VulnerabilitàAlta
CVE-2026-4558 (CVSS 8.8)

A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)22 mar 2026
VulnerabilitàAlta
CVE-2026-4558 - Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection

CVE ID :CVE-2026-4558 Published : March 22, 2026, 6:16 p.m. | 9 hours, 36 minutes ago Description :A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4557 - code-projects Exam Form Submission update_s1.php cross site scripting

CVE ID :CVE-2026-4557 Published : March 22, 2026, 6:16 p.m. | 9 hours, 36 minutes ago Description :A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s1.php. Performing a manipulation of the argument sname results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4555 (CVSS 8.8)

A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

NVD (NIST)22 mar 2026
VulnerabilitàAlta
CVE-2026-33319 - AVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command

CVE ID :CVE-2026-33319 Published : March 22, 2026, 5:17 p.m. | 10 hours, 35 minutes ago Description :WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an upload URL received from LinkedIn's API response, without sanitization via `escapeshellarg()`. If an attacker can influence the LinkedIn API response (via MITM, compromised OAuth token, or API compromise), they can inject arbitrary OS commands that execute as the web server user. Version 26.0 contains a fix for the issue. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4555 - D-Link DIR-513 boa formEasySetTimezone memory corruption

CVE ID :CVE-2026-4555 Published : March 22, 2026, 5:17 p.m. | 10 hours, 35 minutes ago Description :A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-33296 - AVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php

CVE ID :CVE-2026-33296 Published : March 22, 2026, 5:17 p.m. | 10 hours, 35 minutes ago Description :WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected directly into a JavaScript `document.location` assignment without JavaScript-safe encoding. After a user completes the login popup flow, a timer callback executes the redirect using the unvalidated value, sending the victim to an attacker-controlled site. Version 26.0 fixes the issue. Severity: 2.1 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4554 - Tenda F453 WriteFacMac FormWriteFacMac privilege escalation

CVE ID :CVE-2026-4554 Published : March 22, 2026, 5:17 p.m. | 10 hours, 35 minutes ago Description :A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-33294 - AVideo has SSRF in BulkEmbed Thumbnail Fetch that Allows Reading Internal Network Resources

CVE ID :CVE-2026-33294 Published : March 22, 2026, 5:17 p.m. | 10 hours, 35 minutes ago Description :WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents()` without SSRF protection. Unlike all six other URL-fetching endpoints in AVideo that were hardened with `isSSRFSafeURL()`, this code path was missed. An authenticated attacker can force the server to make HTTP requests to internal network resources and retrieve the responses by viewing the saved video thumbnail. Version 26.0 fixes the issue. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-33295 - AVideo Vulnerable to Stored XSS via Unescaped Video Title in CDN downloadButtons.php

CVE ID :CVE-2026-33295 Published : March 22, 2026, 5:17 p.m. | 10 hours, 35 minutes ago Description :WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated directly into a JavaScript string literal without any escaping, allowing an attacker who can create or modify a video to inject arbitrary JavaScript that executes in the browser of any user who visits the affected download page. Version 26.0 fixes the issue. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-33292 - AVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid Videos

CVE ID :CVE-2026-33292 Published : March 22, 2026, 5:17 p.m. | 10 hours, 35 minutes ago Description :WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to stream any private or paid video on the platform. The `videoDirectory` GET parameter is used in two divergent code paths — one for authorization (which truncates at the first `/` segment) and one for file access (which preserves `..` traversal sequences) — creating a split-oracle condition where authorization is checked against one video while content is served from another. Version 26.0 contains a fix for the issue. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-33293 - AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter

CVE ID :CVE-2026-33293 Published : March 22, 2026, 5:17 p.m. | 10 hours, 35 minutes ago Description :WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitization. An attacker with valid clone credentials can use path traversal sequences (e.g., `../../`) to delete arbitrary files on the server, including critical application files such as `configuration.php`, causing complete denial of service or enabling further attacks by removing security-critical files. Version 26.0 fixes the issue. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026

Pagina 3209 di 3796

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.