Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

30444 risultati

VulnerabilitàAlta
CVE-2026-11334 (CVSS 7.3)

A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This affects an unknown function of the file dashboard_page/forms/fetch.php. Performing a manipulation of the argument department_code results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

NVD (NIST)05 giu 2026
VulnerabilitàAlta
CVE-2026-11335 - tittuvarghese CollegeManagementSystem login-form.php session_start session fixiation

CVE ID :CVE-2026-11335 Published : June 5, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This impacts the function session_start of the file /login-form.php. Executing a manipulation of the argument UserAuthData can lead to session fixiation. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-11333 - tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload

CVE ID :CVE-2026-11333 Published : June 5, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. The impacted element is an unknown function of the file dashboard_page/forms/upload_student_data.php of the component Student Data Upload Endpoint. Such manipulation of the argument Student-Data-CSV leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-11334 - tittuvarghese CollegeManagementSystem fetch.php sql injection

CVE ID :CVE-2026-11334 Published : June 5, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This affects an unknown function of the file dashboard_page/forms/fetch.php. Performing a manipulation of the argument department_code results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-37737 - Sanic-CORS Regex Bypass Vulnerability

CVE ID :CVE-2026-37737 Published : June 5, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match without end-anchoring. This allows an attacker to bypass CORS origin allowlists by registering a domain that begins with a trusted origin string, to gain unauthorized access to cross-origin requests for authenticated resources. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-10879 - DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders

CVE ID :CVE-2026-10879 Published : June 5, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2025-59174 - Ericsson Packet Core Controller Denial of Service

CVE ID :CVE-2025-59174 Published : June 5, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2020-25900 - HelloTalk GPS Data Leak

CVE ID :CVE-2020-25900 Published : June 5, 2026, 3:16 p.m. | 1 hour, 16 minutes ago Description :HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.) Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026
VulnerabilitàAlta
CVE-2026-50234 (CVSS 7.5)

Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directory traversal in the web server context. Attackers can manipulate file path parameters to access sensitive files outside the intended directory structure.

NVD (NIST)05 giu 2026
VulnerabilitàAlta
CVE-2026-50232 (CVSS 7.2)

Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through media file metadata tags like GENRE, ARTIST, and ALBUM. Attackers can craft files with XSS payloads in metadata tags that execute in the web interface when users view track information or play files, enabling access to management functions and settings disclosure.

NVD (NIST)05 giu 2026
VulnerabilitàAlta
CVE-2026-50231 (CVSS 7.2)

Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that allows attackers to inject malicious scripts by exploiting unescaped template variables. Attackers can inject XSS payloads through search, lines, and path query parameters or by crafting values that get logged such as URLs, User-Agent headers, stream titles, or player names to execute arbitrary scripts in users' browsers.

NVD (NIST)05 giu 2026
VulnerabilitàAlta
CVE-2026-50232 - Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags

CVE ID :CVE-2026-50232 Published : June 5, 2026, 2:16 p.m. | 2 hours, 16 minutes ago Description :Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through media file metadata tags like GENRE, ARTIST, and ALBUM. Attackers can craft files with XSS payloads in metadata tags that execute in the web interface when users view track information or play files, enabling access to management functions and settings disclosure. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE05 giu 2026

Pagina 847 di 2537

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.