Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

17693 risultati

VulnerabilitàAlta
CVE-2026-1540 - Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution

CVE ID :CVE-2026-1540 Published : April 2, 2026, 6:16 a.m. | 1 hour, 38 minutes ago Description :The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-5322 - AlejandroArciniegas mcp-data-vis MCP server.js request sql injection

CVE ID :CVE-2026-5322 Published : April 2, 2026, 5:30 a.m. | 24 minutes ago Description :A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the function Request of the file src/servers/database/server.js of the component MCP Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-4347 - MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir

CVE ID :CVE-2026-4347 Published : April 2, 2026, 5:28 a.m. | 26 minutes ago Description :The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php). The vulnerability is only exploitable if a file upload field is added to the form and the “Saving inquiry data in database” option is enabled. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-5321 - vanna-ai vanna FastAPI/Flask Server cross-domain policy

CVE ID :CVE-2026-5321 Published : April 2, 2026, 5:16 a.m. | 2 hours, 38 minutes ago Description :A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the component FastAPI/Flask Server. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-5320 (CVSS 7.3)

A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of the component Chat API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD (NIST)02 apr 2026
VulnerabilitàAlta
CVE-2026-5320 - vanna-ai vanna Chat API Endpoint v2 missing authentication

CVE ID :CVE-2026-5320 Published : April 2, 2026, 5:16 a.m. | 2 hours, 38 minutes ago Description :A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of the component Chat API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
VulnerabilitàAlta
CVE-2026-5318 - LibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds write

CVE ID :CVE-2026-5318 Published : April 2, 2026, 3:16 a.m. | 4 hours, 38 minutes ago Description :A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
News
Cisco Issues Urgent Patch for Critical IMC Auth Bypass: A CVSS 9.8 Wake-Up Call

Cisco Issues Urgent Patch for Critical IMC Auth Bypass: A CVSS 9.8 Wake-Up Call A newly discovered vulnerability has turned the Cisco Integrated Management Controller (IMC) into a potential backdoor. Tracked as CVE-2026-20093, this critical flaw carries a CVSS score of 9.8, signa ... Read more Published Date: Apr 02, 2026 (23 hours, 59 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-20160 CVE-2026-20093 CVE-2026-5281 CVE-2026-3502 CVE-2026-33032 CVE-2026-21962 CVE-2025-6388 CVE-2025-10159 CVE-2025-20241 CVE-2024-20401

CVEfeed Newsroom02 apr 2026
VulnerabilitàAlta
CVE-2026-5319 - itsourcecode Payroll Management System navbar.php cross site scripting

CVE ID :CVE-2026-5319 Published : April 2, 2026, 4:16 a.m. | 3 hours, 37 minutes ago Description :A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE02 apr 2026
News
Critical 9.8 CVSS Flaw in Cisco SSM On-Prem Grants Unauthenticated Root Access

Critical 9.8 CVSS Flaw in Cisco SSM On-Prem Grants Unauthenticated Root Access Cisco has recently dropped a high-stakes security advisory regarding a critical vulnerability in its Smart Software Manager On-Prem (SSM On-Prem). Labeled as CVE-2026-20160, this flaw carries a CVSS s ... Read more Published Date: Apr 02, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-20160 CVE-2026-20093 CVE-2026-5281 CVE-2026-34156 CVE-2026-3502 CVE-2026-33032 CVE-2026-21962 CVE-2025-20265 CVE-2025-20309 CVE-2025-20260 CVE-2025-20188

CVEfeed Newsroom02 apr 2026
News
Vim Modeline Bypass Vulnerability Let Attackers Execute Arbitrary OS Commands

Vim Modeline Bypass Vulnerability Let Attackers Execute Arbitrary OS Commands A newly discovered high-severity vulnerability in the popular Vim text editor exposes users to arbitrary command execution on the operating system. Tracked as CVE-2026-34982, the flaw relies on a mode ... Read more Published Date: Apr 02, 2026 (18 hours, 21 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom02 apr 2026
News
Public PoC Exploit Released for Nginx-UI Backup Restore Vulnerability

Public PoC Exploit Released for Nginx-UI Backup Restore Vulnerability A critical security flaw has been disclosed in the Nginx-UI backup restore mechanism, tracked as CVE-2026-33026. This vulnerability allows threat actors to tamper with encrypted backup archives and in ... Read more Published Date: Apr 02, 2026 (14 hours, 23 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-33026

CVEfeed Newsroom02 apr 2026

Pagina 723 di 1475

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.