Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

29137 risultati

VulnerabilitàAlta
CVE-2026-11616 (CVSS 8.8)

The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled $_POST['type'] and $_POST['postid'] values before forwarding them to update_ayi_data(), which calls update_user_meta($current_user->ID, $rsvp_args['type'], $posts). By passing type=wp_capabilities and postid=administrator, an attacker writes ['subscriber'=>true,'administrator'=>'administrator'] into their own wp_capabilities user meta; WP_User::get_role_caps() then treats the 'administrator' array key as an active role on the next request. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator.

NVD (NIST)09 giu 2026
VulnerabilitàAlta
CVE-2026-25688 - Apache Answer: XSS in AI Answer Rendering

CVE ID :CVE-2026-25688 Published : June 9, 2026, 9:16 a.m. | 1 hour, 19 minutes ago Description :Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-25699 - Apache Answer: Authorization Bypass in Timeline API

CVE ID :CVE-2026-25699 Published : June 9, 2026, 9:16 a.m. | 1 hour, 19 minutes ago Description :Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-9698 - DBI versions before 1.648 for Perl saved errors in a limited-sized buffer

CVE ID :CVE-2026-9698 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-5068 - bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data

CVE ID :CVE-2026-5068 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf) and the chosen RX pool has a user_data_size smaller than 2 bytes, the segmentation counter stored in the net_buf user_data area is written out of bounds in l2cap_chan_le_recv_seg (subsys/bluetooth/host/l2cap.c). The observed effects are an AddressSanitizer abort and, without ASan, heap corruption / fatal error. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-41984 - Vendor Package Manager Use-After-Free

CVE ID :CVE-2026-41984 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity. Severity: 5.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-41985 - Package Management Module Use-After-Free Vulnerability

CVE ID :CVE-2026-41985 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-41986 - ACME File System Logic Bypass Denial of Service

CVE ID :CVE-2026-41986 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 2.4 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-41983 - Browser Kernel DoS Vulnerability

CVE ID :CVE-2026-41983 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :DoS vulnerability in the browser kernel. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-44083 - QuMagie

CVE ID :CVE-2026-44083 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-41982 - [Vendor] IPC Module Race Condition Denial-of-Service

CVE ID :CVE-2026-41982 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026
VulnerabilitàAlta
CVE-2026-41981 - IPC Module Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-41981 Published : June 9, 2026, 8:16 a.m. | 19 minutes ago Description :Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 giu 2026

Pagina 697 di 2429

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.