Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

29134 risultati

VulnerabilitàAlta
CVE-2026-11788 - 389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser

CVE ID :CVE-2026-11788 Published : June 9, 2026, 2:16 p.m. | 19 minutes ago Description :A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-11787 - 389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing

CVE ID :CVE-2026-11787 Published : June 9, 2026, 2:16 p.m. | 19 minutes ago Description :A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-11785 - 389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in sso token handler

CVE ID :CVE-2026-11785 Published : June 9, 2026, 2:16 p.m. | 19 minutes ago Description :A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
News
Vulnerabilities in Logseq software

Vulnerabilities in Logseq software Vulnerabilities in Logseq software CVE ID CVE-2026-9279 Publication date 09 June 2026 Vendor Logseq Product Logseq Vulnerable versions All through 0.10.15 Vulnerability type (CWE) Improper Neutralizat ... Read more Published Date: Jun 09, 2026 (1 day, 11 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 giu 2026
News
CISA adds BerriAI LiteLLM & Check Point Security Gateway to KEV

CISA adds BerriAI LiteLLM & Check Point Security Gateway to KEV CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog on June 8, 2026, confirming active exploitation of both. The two entries are CVE-2026-42271 (BerriAI LiteLLM Command Injec ... Read more Published Date: Jun 09, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-50752 CVE-2026-50751 CVE-2026-28318 CVE-2026-48710 CVE-2026-42271 CVE-2026-42208

CVEfeed Newsroom09 giu 2026
VulnerabilitàCritica
CVE-2017-20251 (CVSS 9.8)

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with crafted content containing insert_php shortcodes to include and execute remote PHP files on the server.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2017-20250 (CVSS 7.5)

Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin directory.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2017-20249 (CVSS 8.2)

Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attackers can send GET requests with crafted SQL payloads in the albid parameter to extract sensitive database information including user credentials and authentication hashes.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2017-20248 (CVSS 7.5)

Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests to asgallDownload.php with directory traversal sequences ../ to access sensitive files outside the intended directory.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2017-20247 (CVSS 8.2)

WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid parameter. Attackers can send GET requests with crafted SQL payloads in the aid parameter to extract sensitive database information including user credentials and table contents.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2017-20246 (CVSS 8.2)

KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can inject SQL code through the 'kc_ad' parameter in base.css.php or kittycatfish.php to extract sensitive database information using boolean-based blind or time-based blind techniques.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2017-20245 (CVSS 8.2)

Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup' parameter to read arbitrary data from the database.

NVD (NIST)09 giu 2026

Pagina 692 di 2428

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.