Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45707 risultati

VulnerabilitàAlta
CVE-2026-3334 (CVSS 8.8)

The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries in the restore workflow. This makes it possible for authenticated attackers, with CMS Commander API key access, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-3003 (CVSS 7.2)

The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-2941 (CVSS 8.8)

The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to update any database table, any value, including the wp_capabilities database field, which allows attackers to change their own role to administrator, which leads to privilege escalation.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-2468 (CVSS 7.5)

The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to, and including, 1.2.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `get_user_access()` method. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-2440 (CVSS 7.2)

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.3 via survey result submissions. This is due to insufficient input sanitization and output escaping. The public survey page exposes the nonce required for submission, allowing unauthenticated attackers to submit HTML-encoded payloads that are decoded and rendered as executable HTML when an administrator views survey results, leading to stored XSS in the admin context.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-2279 (CVSS 7.2)

The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all versions up to, and including, 1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-1800 (CVSS 7.5)

The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedFnt’ parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-1648 (CVSS 7.2)

The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations, including internal services, via the Gopher protocol and other dangerous protocols. This can be exploited to achieve Remote Code Execution by chaining with services like Redis.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-1313 (CVSS 8.3)

The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is enabled. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services via crafted links in post content.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2025-14037 (CVSS 8.1)

The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2.6. This is due to missing validation and sanitization in the 'createManageFeedPage' function. This makes it possible for authenticated administrator-level attackers to delete arbitrary files on the server via specially crafted requests that include path traversal sequences, granted they can trick an admin into clicking a malicious link.

NVD (NIST)21 mar 2026
News
Critical 9.3 CVSS Flaw in QNAP QVR Pro Exposes Surveillance Systems

Critical 9.3 CVSS Flaw in QNAP QVR Pro Exposes Surveillance Systems QNAP Systems, Inc. has issued a critical security advisory for users of its QVR Pro surveillance solution. A high-severity vulnerability, tracked as CVE-2026-22898 with a CVSS score of 9.3, could allo ... Read more Published Date: Mar 21, 2026 (2 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22898 CVE-2026-21992 CVE-2025-32975 CVE-2022-27595 CVE-2024-48861 CVE-2024-48860

CVEfeed Newsroom21 mar 2026
News
Critical 9.8 CVSS Flaw Exposes Oracle Identity Manager to Total Takeover

Critical 9.8 CVSS Flaw Exposes Oracle Identity Manager to Total Takeover Oracle has issued an urgent security alert following the discovery of a “Critical” rated vulnerability impacting its Fusion Middleware ecosystem. The flaw, tracked as CVE-2026-21992, carries a CVSS sc ... Read more Published Date: Mar 21, 2026 (2 days, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22898 CVE-2026-21992 CVE-2026-21994 CVE-2025-61884 CVE-2025-32975 CVE-2024-21182

CVEfeed Newsroom21 mar 2026

Pagina 3238 di 3809

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.