Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

46675 risultati

VulnerabilitàAlta
CVE-2026-33170 - Rails Active Support has a possible XSS vulnerability in SafeBuffer#%

CVE ID :CVE-2026-33170 Published : March 23, 2026, 11:09 p.m. | 42 minutes ago Description :Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `SafeBuffer#%` does not propagate the `@html_unsafe` flag to the newly created buffer. If a `SafeBuffer` is mutated in place (e.g. via `gsub!`) and then formatted with `%` using untrusted arguments, the result incorrectly reports `html_safe? == true`, bypassing ERB auto-escaping and possibly leading to XSS. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-33169 - Rails Active Support has a possible ReDoS vulnerability in number_to_delimited

CVE ID :CVE-2026-33169 Published : March 23, 2026, 11:07 p.m. | 45 minutes ago Description :Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regular expression with `gsub!` to insert thousands delimiters. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, the interaction between the repeated lookahead group and `gsub!` can produce quadratic time complexity on long digit strings. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4613 - SourceCodester E-Commerce Site products.php sql injection

CVE ID :CVE-2026-4613 Published : March 23, 2026, 11:04 p.m. | 48 minutes ago Description :A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /products.php. The manipulation of the argument Search results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4612 (CVSS 7.3)

A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the file /hotel/admin/mod_users/index.php?view=edit&id=8 of the component Parameter Handler. The manipulation of the argument account_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-4611 (CVSS 7.2)

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-33634 - Trivy ecosystem supply chain briefly compromised

CVE ID :CVE-2026-33634 Published : March 23, 2026, 10:16 p.m. | 1 hour, 35 minutes ago Description :Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one's environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one's organization pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts immediately. Review all workflows using `aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced a version tag rather than a full commit SHA should check workflow run logs from March 19–20, 2026 for signs of compromise. Look for repositories named `tpcp-docs` in one's GitHub organization. The presence of...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4681 - Critical Remote Code Execution vulnerability reported in Windchill

CVE ID :CVE-2026-4681 Published : March 23, 2026, 10:16 p.m. | 1 hour, 35 minutes ago Description :A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0; FlexPLM: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàCritica
CVE-2026-32913 (CVSS 9.3)

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-32912 - OpenClaw 2026.2.26 < 2026.3.1 - Current Working Directory Injection via Windows Wrapper Resolution Fallback

CVE ID :CVE-2026-32912 Published : March 23, 2026, 10:16 p.m. | 1 hour, 36 minutes ago Description :Rejected reason: This CVE ID has been rejected. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-32911 - OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds

CVE ID :CVE-2026-32911 Published : March 23, 2026, 10:16 p.m. | 1 hour, 36 minutes ago Description :Rejected reason: This CVE ID has been rejected. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-32910 - OpenClaw < 2026.3.1 - Executable Rebind via Unbound PATH-token in system.run Approvals

CVE ID :CVE-2026-32910 Published : March 23, 2026, 10:16 p.m. | 1 hour, 36 minutes ago Description :Rejected reason: This CVE ID has been rejected. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-32278 - Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin

CVE ID :CVE-2026-32278 Published : March 23, 2026, 9:28 p.m. | 23 minutes ago Description :Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Versions 1.41.1 and 2.41.1 contain a patch. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026

Pagina 3287 di 3890

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.