Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45632 risultati

VulnerabilitàAlta
CVE-2019-25581 (CVSS 8.2)

i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers can send GET requests with crafted SQL payloads in the objGroupID parameter to extract sensitive database information including usernames, database names, and version details.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2019-25580 (CVSS 8.2)

ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the IMG parameter to extract sensitive database information including version and database names.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2019-25579 (CVSS 7.5)

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2019-25578 (CVSS 8.2)

phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the idnews parameter. Attackers can send crafted GET requests to GeneratePDF.php with SQL payloads in the idnews parameter to extract sensitive database information or manipulate queries.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2019-25576 (CVSS 8.2)

Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the category parameter. Attackers can send GET requests to the category endpoint with URL-encoded SQL UNION statements to extract database information including usernames, database names, and MySQL version details.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2019-25575 (CVSS 8.2)

SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'p' and 's' parameters. Attackers can send GET requests with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2019-25573 (CVSS 7.1)

Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cat parameter. Attackers can send GET requests to index.php with m=admin, c=posts, a=index parameters and inject SQL code in the cat parameter to manipulate database queries and extract sensitive information.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2019-25582 - i-doit CMDB 1.12 Arbitrary File Download via file_manager Parameter

CVE ID :CVE-2019-25582 Published : March 21, 2026, 4:16 p.m. | 11 hours, 35 minutes ago Description :i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating the file parameter in index.php. Attackers can send GET requests to index.php with file_manager=image and supply arbitrary file paths like src/config.inc.php to retrieve configuration files and sensitive system data. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2019-25581 - i-doit CMDB 1.12 SQL Injection via objGroupID Parameter

CVE ID :CVE-2019-25581 Published : March 21, 2026, 4:16 p.m. | 11 hours, 35 minutes ago Description :i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers can send GET requests with crafted SQL payloads in the objGroupID parameter to extract sensitive database information including usernames, database names, and version details. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2019-25580 - ownDMS 4.7 SQL Injection via pdfstream.php imagestream.php

CVE ID :CVE-2019-25580 Published : March 21, 2026, 4:16 p.m. | 11 hours, 35 minutes ago Description :ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the IMG parameter to extract sensitive database information including version and database names. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2019-25578 - phpTransformer 2016.9 SQL Injection via GeneratePDF.php

CVE ID :CVE-2019-25578 Published : March 21, 2026, 4:16 p.m. | 11 hours, 35 minutes ago Description :phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the idnews parameter. Attackers can send crafted GET requests to GeneratePDF.php with SQL payloads in the idnews parameter to extract sensitive database information or manipulate queries. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2019-25579 - phpTransformer 2016.9 Directory Traversal via jQueryFileUpload

CVE ID :CVE-2019-25579 Published : March 21, 2026, 4:16 p.m. | 11 hours, 35 minutes ago Description :phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026

Pagina 3225 di 3803

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.