Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

15751 risultati

VulnerabilitàAlta
CVE-2026-5555 - code-projects Concert Ticket Reservation System Parameter login.php sql injection

CVE ID :CVE-2026-5555 Published : April 5, 2026, 10:16 a.m. | 5 hours, 39 minutes ago Description :A weakness has been identified in code-projects Concert Ticket Reservation System 1.0. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5554 - code-projects Concert Ticket Reservation System Parameter process_search.php sql injection

CVE ID :CVE-2026-5554 Published : April 5, 2026, 10:16 a.m. | 5 hours, 39 minutes ago Description :A security flaw has been discovered in code-projects Concert Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5550 (CVSS 8.8)

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2026-5550 - Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

CVE ID :CVE-2026-5550 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5548 (CVSS 8.8)

A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.

NVD (NIST)05 apr 2026
VulnerabilitàAlta
CVE-2026-5548 - Tenda AC10 httpd fromSysToolChangePwd stack-based overflow

CVE ID :CVE-2026-5548 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5549 - Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key

CVE ID :CVE-2026-5549 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
News
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited

Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Financial groups lay out a plan to fight AI identity attacks Generative AI tools have brought the cost ... Read more Published Date: Apr 05, 2026 (2 days ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616 CVE-2026-20093 CVE-2026-5281 CVE-2026-3502 CVE-2026-21643

CVEfeed Newsroom05 apr 2026
VulnerabilitàAlta
CVE-2026-5546 - Campcodes Complete Online Learning Management System Crud_model.php add_lesson unrestricted upload

CVE ID :CVE-2026-5546 Published : April 5, 2026, 7:16 a.m. | 4 hours, 39 minutes ago Description :A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5547 - Tenda AC10 httpd formAddMacfilterRule os command injection

CVE ID :CVE-2026-5547 Published : April 5, 2026, 8:16 a.m. | 5 hours, 39 minutes ago Description :A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such manipulation leads to os command injection. It is possible to launch the attack remotely. Multiple endpoints might be affected. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 apr 2026
VulnerabilitàAlta
CVE-2026-5544 (CVSS 8.8)

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the argument Profile results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)05 apr 2026
News
Fortinet waarschuwt voor actief misbruik van kritiek lek in FortiClient EMS

Fortinet waarschuwt voor actief misbruik van kritiek lek in FortiClient EMS Fortinet waarschuwt voor actief misbruik van een kritiek beveiligingslek in FortiClient EMS waardoor een ongeauthenticeerde aanvaller willekeurige code of commando's op het systeem kan uitvoeren. Orga ... Read more Published Date: Apr 05, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616

CVEfeed Newsroom05 apr 2026

Pagina 519 di 1313

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.