Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

44357 risultati

VulnerabilitàAlta
CVE-2026-75553 - Tohoku Electric Power Yorisou e Net Hard-Coded Cryptographic Key Vulnerability

CVE ID :CVE-2026-75553 Published : Sept. 25, 2026, 6:25 a.m. | 53 minutes ago Description :Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product. Severity: 2.4 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-97721 - Sanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsContentAdminController authorization

CVE ID :CVE-2026-97721 Published : Sept. 25, 2026, 6:16 a.m. | 1 hour, 1 minute ago Description :A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/controller/admin/sys/SysUserAdminController.java of the component exportExcel/exportData. This manipulation of the argument userId/deptId causes authorization bypass. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-97846 - Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key binding

CVE ID :CVE-2026-97846 Published : Sept. 25, 2026, 6:16 a.m. | 1 hour, 1 minute ago Description :Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate. A flaw was discovered where the new Standard Token Exchange V2 feature does not check for this certificate. This allows an attacker with stolen client credentials to obtain a standard, unrestricted token that bypasses these security protections. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-78393 - Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb Links

CVE ID :CVE-2026-78393 Published : Sept. 25, 2026, 6 a.m. | 1 hour, 18 minutes ago Description :The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could be used against any visitor, including logged-in administrators. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-78397 - Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation

CVE ID :CVE-2026-78397 Published : Sept. 25, 2026, 6 a.m. | 1 hour, 18 minutes ago Description :The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its safe request is rejected, allowing unauthenticated visitors to make the site issue requests to hosts on its internal network and to learn from the response whether an internal service answered. Versions below 7.8.8 are covered by CVE-2025-68600; this entry covers 7.8.8 through 7.9.5, where that fix was incomplete. Exploitation requires the site owner to have published the Link Library WordPress plugin before 7.9.6's public link submission form with reciprocal-link validation enabled. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-78394 - Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter

CVE ID :CVE-2026-78394 Published : Sept. 25, 2026, 6 a.m. | 1 hour, 18 minutes ago Description :The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite image files anywhere the web server can write, including outside the site's document root. The written file name is always numeric with a fixed image extension, so executable code cannot be planted this way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-97818 - phpIPAM User API Authorization Bypass

CVE ID :CVE-2026-97818 Published : Sept. 25, 2026, 5:17 a.m. | 27 minutes ago Description :phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-97737 - Wakapi Account Takeover via User Caching Service Vulnerability

CVE ID :CVE-2026-97737 Published : Sept. 25, 2026, 5:17 a.m. | 27 minutes ago Description :In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-97764 - django-allauth Authentication Rate Limit Bypass

CVE ID :CVE-2026-97764 Published : Sept. 25, 2026, 5:17 a.m. | 27 minutes ago Description :django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit. Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
News
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (K ... Read more Published Date: Sep 25, 2026 (4 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-71362 CVE-2026-5430

CVEfeed Newsroom4g fa
VulnerabilitàAlta
CVE-2026-97736 - TinyAuth Authorization Bypass via Unanchored Regular Expression

CVE ID :CVE-2026-97736 Published : Sept. 25, 2026, 4:17 a.m. | 1 hour, 27 minutes ago Description :tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-97735 - ITFlow SVG File Upload Vulnerability

CVE ID :CVE-2026-97735 Published : Sept. 25, 2026, 4:17 a.m. | 1 hour, 27 minutes ago Description :ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders. Severity: 8.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa

Pagina 86 di 3697

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.