Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45735 risultati

VulnerabilitàAlta
CVE-2026-1313 (CVSS 8.3)

The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is enabled. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services via crafted links in post content.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2025-14037 (CVSS 8.1)

The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2.6. This is due to missing validation and sanitization in the 'createManageFeedPage' function. This makes it possible for authenticated administrator-level attackers to delete arbitrary files on the server via specially crafted requests that include path traversal sequences, granted they can trick an admin into clicking a malicious link.

NVD (NIST)21 mar 2026
News
Critical 9.3 CVSS Flaw in QNAP QVR Pro Exposes Surveillance Systems

Critical 9.3 CVSS Flaw in QNAP QVR Pro Exposes Surveillance Systems QNAP Systems, Inc. has issued a critical security advisory for users of its QVR Pro surveillance solution. A high-severity vulnerability, tracked as CVE-2026-22898 with a CVSS score of 9.3, could allo ... Read more Published Date: Mar 21, 2026 (2 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22898 CVE-2026-21992 CVE-2025-32975 CVE-2022-27595 CVE-2024-48861 CVE-2024-48860

CVEfeed Newsroom21 mar 2026
News
Critical 9.8 CVSS Flaw Exposes Oracle Identity Manager to Total Takeover

Critical 9.8 CVSS Flaw Exposes Oracle Identity Manager to Total Takeover Oracle has issued an urgent security alert following the discovery of a “Critical” rated vulnerability impacting its Fusion Middleware ecosystem. The flaw, tracked as CVE-2026-21992, carries a CVSS sc ... Read more Published Date: Mar 21, 2026 (2 days, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-22898 CVE-2026-21992 CVE-2026-21994 CVE-2025-61884 CVE-2025-32975 CVE-2024-21182

CVEfeed Newsroom21 mar 2026
VulnerabilitàAlta
CVE-2026-4302 (CVSS 7.2)

The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the plugin exposing a publicly accessible REST API endpoint (optn/v1/integration-action) with a permission_callback of __return_true that passes user-supplied URLs directly to wp_remote_get() and wp_remote_post() in the Webhook::add_subscriber() method without any URL validation or restriction. The plugin does not use wp_safe_remote_get/post which provide built-in SSRF protection. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application, which can be used to query and modify information from internal services.

NVD (NIST)21 mar 2026
News
Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution

Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution Google has released a substantial security update for its Chrome web browser, addressing 26 distinct vulnerabilities that could allow unauthenticated attackers to execute malicious code remotely. The ... Read more Published Date: Mar 21, 2026 (2 days, 14 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4464 CVE-2026-4463 CVE-2026-4462 CVE-2026-4461 CVE-2026-4460 CVE-2026-4459 CVE-2026-4458 CVE-2026-4457 CVE-2026-4456 CVE-2026-4455 CVE-2026-4454 CVE-2026-4453 CVE-2026-4452 CVE-2026-4451 CVE-2026-4450 CVE-2026-4449 CVE-2026-4448 CVE-2026-4447 CVE-2026-4446 CVE-2026-4445 CVE-2026-4444 CVE-2026-4443 CVE-2026-4442 CVE-2026-4441 CVE-2026-4440 CVE-2026-4439

CVEfeed Newsroom21 mar 2026
News
Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager Oracle has issued an out-of-band Security Alert addressing a critical remote code execution (RCE) vulnerability, CVE-2026-21992, affecting two widely deployed Fusion Middleware components, Oracle Iden ... Read more Published Date: Mar 21, 2026 (2 days, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-21992

CVEfeed Newsroom21 mar 2026
News
CISA adds Five Vulnerabilities to KEV Catalog- March 20, 2026

CISA adds Five Vulnerabilities to KEV Catalog- March 20, 2026 OverviewCISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog on March 20, 2026, with a remediation due date of April 3, 2026 for all entries. The batch spans three Apple ecos ... Read more Published Date: Mar 21, 2026 (2 days, 13 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20131 CVE-2025-43520 CVE-2025-43510 CVE-2025-31277 CVE-2025-54068 CVE-2025-32432 CVE-2024-58136

CVEfeed Newsroom21 mar 2026
VulnerabilitàAlta
CVE-2026-32899 - OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers

CVE ID :CVE-2026-32899 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message events before adding them to system-event context. Attackers can bypass configured DM policies and channel user allowlists to inject unauthorized reaction and pin events from restricted senders. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32896 - OpenClaw < 2026.2.21 - Unauthenticated Webhook Access via Passwordless Fallback in BlueBubbles Plugin

CVE ID :CVE-2026-32896 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.21 BlueBubbles webhook handler contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass webhook authentication by exploiting the loopback/proxy heuristics to send unauthenticated webhook events to the BlueBubbles plugin. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32897 - OpenClaw < 2026.2.22 - Authentication Token Reuse in Owner ID Prompt Hashing Fallback

CVE ID :CVE-2026-32897 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset, creating dual-use of authentication secrets across security domains. Attackers with access to system prompts sent to third-party model providers can derive the gateway authentication token from the hash outputs, compromising gateway authentication security. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32898 - OpenClaw < 2026.2.23 - ACP Permission Auto-Approval Bypass via Untrusted Tool Metadata

CVE ID :CVE-2026-32898 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted toolCall.kind metadata and permissive name heuristics. Attackers can bypass interactive approval prompts for read-class operations by spoofing tool metadata or using non-core read-like names to reach auto-approve paths. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026

Pagina 3241 di 3812

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.