Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

46902 risultati

News
Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992)

Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) Oracle has released an out-of-band patch for a critical and easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager. The company did not say whethe ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-21992 CVE-2026-20131 CVE-2025-61757

CVEfeed Newsroom23 mar 2026
News
Vulnerability in KlinikaXP and KlinikaXP Insertino software

Vulnerability in KlinikaXP and KlinikaXP Insertino software Vulnerability in KlinikaXP and KlinikaXP Insertino software CVE ID CVE-2026-1958 Publication date 23 March 2026 Vendor BRI Product KlinikaXP and KlinikaXP Insertino Vulnerable versions KlinikaXP: all ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-1958

CVEfeed Newsroom23 mar 2026
News
'Tientallen Nederlandse SharePoint-servers bevatten actief misbruikt lek'

'Tientallen Nederlandse SharePoint-servers bevatten actief misbruikt lek' Tientallen Microsoft SharePoint-servers met een Nederlands ip-adres bevatten een kwetsbaarheid waarvan actief misbruikt wordt gemaakt, zo stelt The Shadowserver Foundation op basis van eigen onderzoek ... Read more Published Date: Mar 23, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20963

CVEfeed Newsroom23 mar 2026
News
$30 IP-KVM Flaws Could Give Attackers BIOS-Level Control Across Enterprise Networks

$30 IP-KVM Flaws Could Give Attackers BIOS-Level Control Across Enterprise Networks $30 IP-KVM Flaws Attackers BIOS-Level Control Across Enterprise Networks A recent security assessment by researchers has uncovered nine severe vulnerabilities across four popular low-cost IP-KVM devic ... Read more Published Date: Mar 23, 2026 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-32298 CVE-2026-32297 CVE-2026-32296 CVE-2026-32295 CVE-2026-32294 CVE-2026-32293 CVE-2026-32292 CVE-2026-32291 CVE-2026-32290

CVEfeed Newsroom23 mar 2026
VulnerabilitàAlta
CVE-2026-4581 (CVSS 7.3)

A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. If you want to get best quality of vulnerability data, you may have to visit VulDB.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-4582 - Shenzhen HCC Technology MPOS M6 PLUS Bluetooth missing authentication

CVE ID :CVE-2026-4582 Published : March 23, 2026, 10:16 a.m. | 3 hours, 36 minutes ago Description :A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionality of the component Bluetooth. Such manipulation leads to missing authentication. The attack must be carried out from within the local network. Attacks of this nature are highly complex. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4581 - code-projects Simple Laundry System Parameters checklogin.php sql injection

CVE ID :CVE-2026-4581 Published : March 23, 2026, 10:16 a.m. | 3 hours, 36 minutes ago Description :A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. If you want to get best quality of vulnerability data, you may have to visit VulDB. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4628 - Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to improper access control

CVE ID :CVE-2026-4628 Published : March 23, 2026, 9:16 a.m. | 4 hours, 35 minutes ago Description :A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false restriction. This occurs due to incomplete enforcement of access control checks on PUT operations to the resource_set endpoint. This issue enables unauthorized modification of protected resources, impacting data integrity. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
VulnerabilitàAlta
CVE-2026-4580 (CVSS 7.3)

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php of the component Parameters Handler. The manipulation of the argument serviceId results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)23 mar 2026
VulnerabilitàAlta
CVE-2026-4580 - code-projects Simple Laundry System Parameters checkupdatestatus.php sql injection

CVE ID :CVE-2026-4580 Published : March 23, 2026, 9:16 a.m. | 4 hours, 36 minutes ago Description :A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php of the component Parameters Handler. The manipulation of the argument serviceId results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 mar 2026
News
CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks

CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks CISA Warns Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain An urgent warning regarding three critical Apple vulnerabilities that threat actors are actively exploiting in the wild. These se ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2025-43520 CVE-2025-43510 CVE-2025-31277

CVEfeed Newsroom23 mar 2026
News
The Undocumented Backdoor: Critical 10.0 CVSS Flaw Hits WAGO Managed Switches

The Undocumented Backdoor: Critical 10.0 CVSS Flaw Hits WAGO Managed Switches A severe vulnerability has been uncovered in several models of WAGO Managed Switches, potentially leaving industrial networks exposed to complete takeover. The flaw, tracked as CVE-2026-3587, has earn ... Read more Published Date: Mar 23, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-3587 CVE-2025-32432

CVEfeed Newsroom23 mar 2026

Pagina 3317 di 3909

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.