Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45612 risultati

VulnerabilitàAlta
CVE-2019-25588 - BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address

CVE ID :CVE-2019-25588 Published : March 22, 2026, 1:16 a.m. | 10 hours, 35 minutes ago Description :BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25589 - ZOC Terminal 7.23.4 Buffer Overflow Denial of Service

CVE ID :CVE-2019-25589 Published : March 22, 2026, 1:16 a.m. | 10 hours, 35 minutes ago Description :ZOC Terminal 7.23.4 contains a buffer overflow vulnerability in the Shell field of Program Settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a crafted payload into the Shell configuration field and trigger a crash when accessing the Command Shell feature. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25585 - Deluge 1.3.15 Denial of Service via Webseeds Field

CVE ID :CVE-2019-25585 Published : March 22, 2026, 1:16 a.m. | 10 hours, 35 minutes ago Description :Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into the Webseeds field during torrent creation to trigger an application crash. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25587 - BulletProof FTP Server 2019.0.0.50 Storage-Path Denial of Service

CVE ID :CVE-2019-25587 Published : March 22, 2026, 1:16 a.m. | 10 hours, 35 minutes ago Description :BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration parameter that allows local attackers to crash the application by supplying an excessively long string value. Attackers can enable the Override Storage-Path setting and paste a buffer of 500 bytes or more to trigger an application crash when saving the configuration. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25583 - RarmaRadio 2.72.3 Username Field Denial of Service

CVE ID :CVE-2019-25583 Published : March 22, 2026, 1:16 a.m. | 8 hours, 35 minutes ago Description :RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes into the Username field via Settings > Network to trigger an application crash. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25584 - RarmaRadio 2.72.3 Server Field Buffer Overflow Denial of Service

CVE ID :CVE-2019-25584 Published : March 22, 2026, 1:16 a.m. | 8 hours, 35 minutes ago Description :RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a malicious payload exceeding 4000 bytes into the Server field via the Settings menu to trigger an application crash. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25586 - Deluge 1.3.15 Denial of Service via URL Field

CVE ID :CVE-2019-25586 Published : March 22, 2026, 1:16 a.m. | 10 hours, 35 minutes ago Description :Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From URL' field during torrent addition to trigger an application crash. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4530 - apconw Aix-DB terminology_retriever.py sql injection

CVE ID :CVE-2026-4530 Published : March 22, 2026, 12:16 a.m. | 7 hours, 36 minutes ago Description :A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriever.py. Performing a manipulation of the argument Description results in sql injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-4529 (CVSS 8.8)

A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-3629 (CVSS 8.1)

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' method does not include sensitive meta keys such as 'wp_capabilities'. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator by submitting a crafted registration request that sets the 'wp_capabilities' meta key. The vulnerability can only be exploited if the "Show fields in profile" setting is enabled and a CSV with a wp_capabilities column header has been previously imported.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-3629 - Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator via save_extra_user_profile_fields

CVE ID :CVE-2026-3629 Published : March 21, 2026, 11:16 p.m. | 8 hours, 35 minutes ago Description :The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' method does not include sensitive meta keys such as 'wp_capabilities'. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator by submitting a crafted registration request that sets the 'wp_capabilities' meta key. The vulnerability can only be exploited if the "Show fields in profile" setting is enabled and a CSV with a wp_capabilities column header has been previously imported. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-4529 - D-Link DHP-1320 SOAP redirect_count_down_page stack-based overflow

CVE ID :CVE-2026-4529 Published : March 21, 2026, 11:16 p.m. | 8 hours, 35 minutes ago Description :A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026

Pagina 3222 di 3801

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.