Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

29115 risultati

VulnerabilitàAlta
CVE-2026-9019 - Easy Image Collage <= 1.13.6 - Authenticated (Author+) Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters

CVE ID :CVE-2026-9019 Published : June 10, 2026, 8:16 a.m. | 4 hours, 22 minutes ago Description :The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the data is stored via update_post_meta() rather than wp_insert_post() post content, WordPress's unfiltered_html restriction does not apply, meaning Authors cannot be blocked from this attack path by capability controls alone. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-10721 - Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components

CVE ID :CVE-2026-10721 Published : June 10, 2026, 8:16 a.m. | 4 hours, 22 minutes ago Description :Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 for reporting. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
News
Microsoft dicht Windows-kernel remote code execution-lek en BitLocker-bypass

Microsoft dicht Windows-kernel remote code execution-lek en BitLocker-bypass Tijdens de patchdinsdag van juni heeft Microsoft updates voor meer dan tweehonderd kwetsbaarheden uitgebracht, waaronder een beveiligingslek in de Windows-kernel waardoor remote code execution mogelij ... Read more Published Date: Jun 10, 2026 (1 day, 23 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-50507 CVE-2026-47291 CVE-2026-45657 CVE-2026-44815

CVEfeed Newsroom10 giu 2026
News
Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards

Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards On June 9, Anthropic released Claude Fable 5, the most capable model it has ever made, generally available. It also did something unusual: it shipped one model as two products, split not by capability ... Read more Published Date: Jun 10, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-11645 CVE-2026-20230 CVE-2026-23479 CVE-2026-4747

CVEfeed Newsroom10 giu 2026
VulnerabilitàAlta
CVE-2026-29115 - Dahua Denial of Service via Exception Reboot

CVE ID :CVE-2026-29115 Published : June 10, 2026, 7:16 a.m. | 5 hours, 22 minutes ago Description :A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-29116 - Dahua Denial of Service via Exception Reboot

CVE ID :CVE-2026-29116 Published : June 10, 2026, 7:16 a.m. | 5 hours, 22 minutes ago Description :A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-3326 - XStore < 9.7.3 - Unauthenticated SQLi

CVE ID :CVE-2026-3326 Published : June 10, 2026, 7:16 a.m. | 5 hours, 22 minutes ago Description :The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-8071 - Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass

CVE ID :CVE-2026-8071 Published : June 10, 2026, 7:16 a.m. | 5 hours, 22 minutes ago Description :The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-9067 - Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload

CVE ID :CVE-2026-9067 Published : June 10, 2026, 7:16 a.m. | 5 hours, 22 minutes ago Description :The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-9060 - Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style

CVE ID :CVE-2026-9060 Published : June 10, 2026, 7:16 a.m. | 5 hours, 22 minutes ago Description :The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network where the super admin visits the page). Severity: 3.5 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-29114 - Dahua: CA Root Certificate Disclosure Leading to Man-in-the-Middle Attacks

CVE ID :CVE-2026-29114 Published : June 10, 2026, 7:16 a.m. | 5 hours, 22 minutes ago Description :A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudulent certificates trusted by those clients and undermine the certificate trust chain. Severity: 2.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026
VulnerabilitàAlta
CVE-2026-11815 - Insecure Deserialization via MITM in Layer 7 Policy Manager

CVE ID :CVE-2026-11815 Published : June 10, 2026, 7:16 a.m. | 5 hours, 22 minutes ago Description :An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE10 giu 2026

Pagina 667 di 2427

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.