Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

47181 risultati

VulnerabilitàAlta
CVE-2026-94495 (CVSS 7.1)

jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering company identity, stock rules, approval behavior, and printing configuration through the systemConfig endpoint.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-94501 - jshERP through 3.6 Privilege Escalation via userBusiness CRUD

CVE ID :CVE-2026-94501 Published : Sept. 21, 2026, 7:17 p.m. | 1 hour, 12 minutes ago Description :jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tenant. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94497 - jshERP through 3.6 Unauthorized Access via by-id Endpoints

CVE ID :CVE-2026-94497 Published : Sept. 21, 2026, 7:17 p.m. | 1 hour, 12 minutes ago Description :jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94412 (CVSS 8.8)

jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to reset that account's password to a known default value, enabling unauthorized access to other user accounts including administrators.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-94411 (CVSS 8.8)

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and a role ID list to escalate from low-privilege tenant user to tenant administrator.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-94403 (CVSS 8.8)

A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)21 set 2026
VulnerabilitàAlta
CVE-2026-49810 - Dell Command Powershell Provider Information Disclosure Vulnerability

CVE ID :CVE-2026-49810 Published : Sept. 21, 2026, 6:19 p.m. | 11 minutes ago Description :Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94494 - jshERP through 3.6 Tenant Information Disclosure via GET /tenant/info

CVE ID :CVE-2026-94494 Published : Sept. 21, 2026, 6:16 p.m. | 13 minutes ago Description :jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data including login names, validity dates, user quotas, and enabled state across all platform tenants. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94414 - jshERP through 3.6 Missing Authorization via updateBtnStr

CVE ID :CVE-2026-94414 Published : Sept. 21, 2026, 6:16 p.m. | 13 minutes ago Description :jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply arbitrary roleId and btnStr parameters to overwrite button-permission configurations for any role in the tenant without privilege validation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-94413 - jshERP through 3.6 Password Hash Disclosure via /user/info

CVE ID :CVE-2026-94413 Published : Sept. 21, 2026, 6:16 p.m. | 13 minutes ago Description :jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers can request arbitrary user information by supplying user IDs to obtain password hashes usable for offline cracking or direct authentication bypass. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-82163 - Dell Command | Intel vPro Out of Band Incorrect Default Permissions Vulnerability

CVE ID :CVE-2026-82163 Published : Sept. 21, 2026, 6:12 p.m. | 18 minutes ago Description :Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026
VulnerabilitàAlta
CVE-2026-66280

CVE ID :CVE-2026-66280 Published : Sept. 21, 2026, 6:04 p.m. | 25 minutes ago Description :None Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 set 2026

Pagina 399 di 3932

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.