Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

47266 risultati

VulnerabilitàAlta
CVE-2026-4514 - PbootCMS Backend UserController.php access control

CVE ID :CVE-2026-4514 Published : March 21, 2026, 11:17 a.m. | 27 minutes ago Description :A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The attack may be performed from remote. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
News
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution. The vulnerability ... Read more Published Date: Mar 21, 2026 (2 days, 16 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-21992 CVE-2025-61757

CVEfeed Newsroom21 mar 2026
VulnerabilitàAlta
CVE-2026-4513 - vanna-ai vanna base.py ask sql injection

CVE ID :CVE-2026-4513 Published : March 21, 2026, 10:16 a.m. | 1 hour, 28 minutes ago Description :A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-4511 - vanna-ai vanna legacy exec injection

CVE ID :CVE-2026-4511 Published : March 21, 2026, 9:16 a.m. | 2 hours, 29 minutes ago Description :A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src/vanna/legacy. Such manipulation leads to injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
News
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catal ... Read more Published Date: Mar 21, 2026 (2 days, 18 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-43520 CVE-2025-43510 CVE-2025-31277 CVE-2025-54068 CVE-2025-32432

CVEfeed Newsroom21 mar 2026
VulnerabilitàAlta
CVE-2026-4373 (CVSS 7.5)

The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs to the WordPress uploads directory. Combined with an insufficient same-file check in 'File_Tools::is_same_file' that only compares basenames, this makes it possible for unauthenticated attackers to exfiltrate arbitrary local files as email attachments by submitting a crafted form request when the form is configured with a Media Field and a Send Email action with file attachment.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-4510 - PbootCMS Parameter MemberController.php alert_location cross site scripting

CVE ID :CVE-2026-4510 Published : March 21, 2026, 7:16 a.m. | 4 hours, 28 minutes ago Description :A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the argument backurl causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-4373 - JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field

CVE ID :CVE-2026-4373 Published : March 21, 2026, 7:16 a.m. | 4 hours, 28 minutes ago Description :The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs to the WordPress uploads directory. Combined with an insufficient same-file check in 'File_Tools::is_same_file' that only compares basenames, this makes it possible for unauthenticated attackers to exfiltrate arbitrary local files as email attachments by submitting a crafted form request when the form is configured with a Media Field and a Send Email action with file attachment. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-4509 - PbootCMS File Upload file.php incomplete blacklist

CVE ID :CVE-2026-4509 Published : March 21, 2026, 6:16 a.m. | 5 hours, 28 minutes ago Description :A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-4261 (CVSS 8.8)

The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_role' meta through the 'save_extra_user_profile_fields' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-4261 - Expire Users <= 1.2.2 - Authenticated (Subscriber+) Privilege Escalation to Administrator via save_extra_user_profile_fields

CVE ID :CVE-2026-4261 Published : March 21, 2026, 4:17 a.m. | 7 hours, 27 minutes ago Description :The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_role' meta through the 'save_extra_user_profile_fields' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-4161 - Review Map by RevuKangaroo <= 1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings

CVE ID :CVE-2026-4161 Published : March 21, 2026, 4:17 a.m. | 7 hours, 27 minutes ago Description :The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026

Pagina 3365 di 3939

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.