Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

15735 risultati

VulnerabilitàAlta
CVE-2026-5548 (CVSS 8.8)

A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2026-5548 - Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

CVE ID :CVE-2026-5548 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5549 - Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key

CVE ID :CVE-2026-5549 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
News
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited

Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Financial groups lay out a plan to fight AI identity attacks Generative AI tools have brought the cost ... Read more Published Date: Apr 05, 2026 (2 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616 CVE-2026-20093 CVE-2026-5281 CVE-2026-3502 CVE-2026-21643

CVEfeed Newsroom05 apr 2026
VulnerabilitàAlta
CVE-2026-5546 - Campcodes Complete Online Learning Management System Crud_model.php add_lesson unrestricted upload

CVE ID :CVE-2026-5546 Published : April 5, 2026, 7:16 a.m. | 4 hours, 39 minutes ago Description :A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5547 - Tenda AC10 httpd formAddMacfilterRule os command injection

CVE ID :CVE-2026-5547 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such manipulation leads to os command injection. It is possible to launch the attack remotely. Multiple endpoints might be affected. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5544 (CVSS 8.8)

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the argument Profile results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)05 apr 2026
News
Fortinet waarschuwt voor actief misbruik van kritiek lek in FortiClient EMS

Fortinet waarschuwt voor actief misbruik van kritiek lek in FortiClient EMS Fortinet waarschuwt voor actief misbruik van een kritiek beveiligingslek in FortiClient EMS waardoor een ongeauthenticeerde aanvaller willekeurige code of commando's op het systeem kan uitvoeren. Orga ... Read more Published Date: Apr 05, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616

CVEfeed Newsroom05 apr 2026
VulnerabilitàAlta
CVE-2026-5541 - code-projects Simple Laundry System Parameter modmemberinfo.php cross site scripting

CVE ID :CVE-2026-5541 Published : April 5, 2026, 5:16 a.m. | 6 hours, 39 minutes ago Description :A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /modmemberinfo.php of the component Parameter Handler. Performing a manipulation of the argument userid results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5543 - PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection

CVE ID :CVE-2026-5543 Published : April 5, 2026, 5:16 a.m. | 6 hours, 39 minutes ago Description :A vulnerability was identified in PHPGurukul User Registration & Login and User Management System 3.3. The affected element is an unknown function of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5542 - code-projects Simple Laundry System Parameter modstaffinfo.php cross site scripting

CVE ID :CVE-2026-5542 Published : April 5, 2026, 5:16 a.m. | 6 hours, 39 minutes ago Description :A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /modstaffinfo.php of the component Parameter Handler. Executing a manipulation of the argument userid can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5540 (CVSS 7.3)

A vulnerability has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modifymember.php of the component Parameter Handler. Such manipulation of the argument firstName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

NVD (NIST)05 apr 2026

Pagina 518 di 1312

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.