Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

46396 risultati

VulnerabilitàAlta
CVE-2019-25635 (CVSS 8.2)

Zeeways Matrimony CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the profile_list endpoint. Attackers can inject SQL code via the up_cast, s_mother, and s_religion parameters to extract sensitive database information using time-based or error-based techniques.

NVD (NIST)24 mar 2026
VulnerabilitàAlta
CVE-2019-25634 (CVSS 8.4)

Base64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input file that overflows a buffer, overwrites the SEH chain with a POP-POP-RET gadget address, and uses an egghunter payload to locate and execute shellcode for code execution.

NVD (NIST)24 mar 2026
VulnerabilitàAlta
CVE-2019-25633 (CVSS 8.4)

AIDA64 Extreme 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input through the email preferences and report wizard interfaces. Attackers can inject crafted payloads into the Display name field and Load from file parameter to trigger the overflow and execute shellcode with application privileges.

NVD (NIST)24 mar 2026
VulnerabilitàAlta
CVE-2019-25631 (CVSS 8.4)

AIDA64 Business 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH pointers with malicious shellcode. Attackers can inject egg hunter shellcode through the SMTP display name field in preferences or report wizard functionality to trigger the overflow and execute code with application privileges.

NVD (NIST)24 mar 2026
VulnerabilitàAlta
CVE-2019-25630 (CVSS 8.8)

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

NVD (NIST)24 mar 2026
VulnerabilitàAlta
CVE-2019-25629 (CVSS 8.4)

AIDA64 Extreme 5.99.4900 contains a structured exception handler buffer overflow vulnerability in the logging functionality that allows local attackers to execute arbitrary code by supplying a malicious CSV log file path. Attackers can inject shellcode through the Hardware Monitoring logging preferences to overflow the buffer and trigger code execution when the application processes the log file path.

NVD (NIST)24 mar 2026
VulnerabilitàCritica
CVE-2019-25628 (CVSS 9.8)

Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded shellcode when imported through the application's web page import functionality.

NVD (NIST)24 mar 2026
VulnerabilitàAlta
CVE-2019-25627 (CVSS 8.4)

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.

NVD (NIST)24 mar 2026
VulnerabilitàAlta
CVE-2019-25626 (CVSS 8.4)

River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbitrary code by supplying a malicious activation code string. Attackers can craft a buffer containing 608 bytes of junk data followed by shellcode and SEH chain overwrite values to trigger code execution when the activation dialog processes the input.

NVD (NIST)24 mar 2026
News
Vulnerabilities from years ago still opening doors for attackers

Vulnerabilities from years ago still opening doors for attackers Exploitation timelines continued to compress in enterprise environments, with newly disclosed flaws reaching active use almost immediately and older weaknesses remaining active years after disclosure. ... Read more Published Date: Mar 24, 2026 (1 day, 16 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-59718 CVE-2025-55182

CVEfeed Newsroom24 mar 2026
News
Exploitkit voor het hacken van kwetsbare iPhones gepubliceerd op internet

Exploitkit voor het hacken van kwetsbare iPhones gepubliceerd op internet Een exploitkit voor het hacken van kwetsbare iPhones is gepubliceerd op internet, wat de kans op grootschalig misbruik vergroot. Vorige week waarschuwden Google, Lookout en iVerify voor een exploitkit ... Read more Published Date: Mar 24, 2026 (1 day, 15 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20700 CVE-2025-43529 CVE-2025-14174

CVEfeed Newsroom24 mar 2026
VulnerabilitàAlta
CVE-2019-25647 - PhreeBooks ERP 5.2.3 Remote Code Execution via Image Manager

CVE ID :CVE-2019-25647 Published : March 24, 2026, 11:27 a.m. | 25 minutes ago Description :PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute arbitrary PHP files by bypassing file extension controls. Attackers can upload malicious PHP files through the image manager endpoint and execute them to establish reverse shell connections and execute system commands. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 mar 2026

Pagina 3252 di 3867

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.