Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

47216 risultati

VulnerabilitàAlta
CVE-2026-3427 - Yoast SEO <= 27.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute

CVE ID :CVE-2026-3427 Published : March 22, 2026, 4:16 a.m. | 7 hours, 35 minutes ago Description :The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `jsonText` block attribute in all versions up to, and including, 27.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4314 - The Ultimate WordPress Toolkit – WP Extended <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation via Menu Editor Module

CVE ID :CVE-2026-4314 Published : March 22, 2026, 4:16 a.m. | 7 hours, 35 minutes ago Description :The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequest()` method in the Menu Editor module using an insecure `strpos()` check against `$_SERVER['REQUEST_URI']` to determine if a request targets the dashboard or profile page. The `grantVirtualCaps()` method, which is hooked into the `user_has_cap` filter, grants elevated capabilities including `manage_options` when this check returns true. This makes it possible for authenticated attackers, with Subscriber-level access and above, to gain administrative capabilities by appending a crafted query parameter to any admin URL, allowing them to update arbitrary WordPress options and ultimately create new Administrator accounts. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4533 - code-projects Simple Food Ordering System all-tickets.php sql injection

CVE ID :CVE-2026-4533 Published : March 22, 2026, 3:16 a.m. | 8 hours, 36 minutes ago Description :A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-tickets.php. The manipulation of the argument Status results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-33550 - SOGo OTP Weakness

CVE ID :CVE-2026-33550 Published : March 22, 2026, 3:16 a.m. | 8 hours, 36 minutes ago Description :SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended). Severity: 2.0 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-33549 - SPIP Unintended Privilege Assignment Vulnerability

CVE ID :CVE-2026-33549 Published : March 22, 2026, 3:16 a.m. | 8 hours, 36 minutes ago Description :SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2025-71276 - SOGo Cross-Site Scripting Vulnerability

CVE ID :CVE-2025-71276 Published : March 22, 2026, 3:16 a.m. | 8 hours, 36 minutes ago Description :SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4532 - code-projects Simple Food Ordering System Database Backup food.sql file access

CVE ID :CVE-2026-4532 Published : March 22, 2026, 2:16 a.m. | 9 hours, 36 minutes ago Description :A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. It is recommended to change the configuration settings. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2026-4531 - Free5GC AMF handler.go HandleRegistrationComplete denial of service

CVE ID :CVE-2026-4531 Published : March 22, 2026, 2:15 a.m. | 9 hours, 36 minutes ago Description :A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF. Executing a manipulation can lead to denial of service. The attack may be performed from remote. This patch is called 52e9386401ce56ea773c5aa587d4cdf7d53da799. It is best practice to apply a patch to resolve this issue. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25588 - BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address

CVE ID :CVE-2019-25588 Published : March 22, 2026, 1:16 a.m. | 10 hours, 35 minutes ago Description :BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25589 - ZOC Terminal 7.23.4 Buffer Overflow Denial of Service

CVE ID :CVE-2019-25589 Published : March 22, 2026, 1:16 a.m. | 10 hours, 35 minutes ago Description :ZOC Terminal 7.23.4 contains a buffer overflow vulnerability in the Shell field of Program Settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a crafted payload into the Shell configuration field and trigger a crash when accessing the Command Shell feature. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25587 - BulletProof FTP Server 2019.0.0.50 Storage-Path Denial of Service

CVE ID :CVE-2019-25587 Published : March 22, 2026, 1:16 a.m. | 10 hours, 35 minutes ago Description :BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration parameter that allows local attackers to crash the application by supplying an excessively long string value. Attackers can enable the Override Storage-Path setting and paste a buffer of 500 bytes or more to trigger an application crash when saving the configuration. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026
VulnerabilitàAlta
CVE-2019-25586 - Deluge 1.3.15 Denial of Service via URL Field

CVE ID :CVE-2019-25586 Published : March 22, 2026, 1:16 a.m. | 10 hours, 35 minutes ago Description :Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From URL' field during torrent addition to trigger an application crash. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE22 mar 2026

Pagina 3355 di 3935

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.