Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

18164 risultati

VulnerabilitàAlta
CVE-2026-2602 - Twentig <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'featuredImageSizeWidth'

CVE ID :CVE-2026-2602 Published : March 29, 2026, 2:16 a.m. | 9 hours, 37 minutes ago Description :The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
VulnerabilitàAlta
CVE-2026-5020 - Totolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection

CVE ID :CVE-2026-5020 Published : March 29, 2026, 1:15 a.m. | 10 hours, 37 minutes ago Description :A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is now public and may be used. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
VulnerabilitàAlta
CVE-2026-4851 - GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization

CVE ID :CVE-2026-4851 Published : March 29, 2026, 1:15 a.m. | 10 hours, 37 minutes ago Description :GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Calls (RPC) over SSH for Perl. The client connects to remote hosts to execute code on them. A compromised or malicious remote host can execute arbitrary code back on the client through unsafe deserialization in the RPC protocol. read_operation() in lib/GRID/Machine/Message.pm deserialises values from the remote side using eval() $arg .= '$VAR1'; my $val = eval "no strict; $arg"; # line 40-41 $arg is raw bytes from the protocol pipe. A compromised remote host can embed arbitrary perl in the Dumper-formatted response: $VAR1 = do { system("..."); }; This executes on the client silently on every RPC call, as the return values remain correct. This functionality is by design but the trust requirement for the remote host is not documented in the distribution. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
VulnerabilitàAlta
CVE-2026-5021 - Tenda F453 httpd PPTPUserSetting fromPPTPUserSetting stack-based overflow

CVE ID :CVE-2026-5021 Published : March 29, 2026, 2:16 a.m. | 9 hours, 37 minutes ago Description :A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. This manipulation of the argument delno causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE29 mar 2026
VulnerabilitàAlta
CVE-2026-5019 (CVSS 7.3)

A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Parameter Handler. The manipulation of the argument Status leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

NVD (NIST)29 mar 2026
VulnerabilitàAlta
CVE-2026-5019 - code-projects Simple Food Order System Parameter all-orders.php sql injection

CVE ID :CVE-2026-5019 Published : March 29, 2026, 12:16 a.m. | 11 hours, 37 minutes ago Description :A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Parameter Handler. The manipulation of the argument Status leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2026-5018 (CVSS 7.3)

A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

NVD (NIST)28 mar 2026
VulnerabilitàAlta
CVE-2026-5018 - code-projects Simple Food Order System Parameter register-router.php sql injection

CVE ID :CVE-2026-5018 Published : March 28, 2026, 11:16 p.m. | 12 hours, 37 minutes ago Description :A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2026-5017 (CVSS 7.3)

A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipulation of the argument Status results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

NVD (NIST)28 mar 2026
VulnerabilitàAlta
CVE-2026-5017 - code-projects Simple Food Order System Parameter all-tickets.php sql injection

CVE ID :CVE-2026-5017 Published : March 28, 2026, 11:16 p.m. | 12 hours, 37 minutes ago Description :A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipulation of the argument Status results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2026-5016 (CVSS 7.3)

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)28 mar 2026
VulnerabilitàAlta
CVE-2026-5016 - elecV2 elecV2P URL mock eAxios server-side request forgery

CVE ID :CVE-2026-5016 Published : March 28, 2026, 10:15 p.m. | 13 hours, 37 minutes ago Description :A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026

Pagina 823 di 1514

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.